Effective July 25, 2026
Privacy Policy
Checkout Rewards helps you decide which saved payment method, coupon, or gift card to use at checkout. Redeemable details and source images are kept in app-private storage and are not uploaded by Checkout Rewards.
Information we process
- Account information: your email address, name if you provide one, a service-generated user identifier, and authentication session. If you choose Sign in with Apple or Google, that provider sends the identity information and token needed to authenticate you.
- Wallet information: the card products you choose to save, including card names and reward selections. We do not ask for or store full payment-card numbers, security codes, or payment-account credentials.
- Coupons and gift cards: merchant, offer, balance, expiration, and other metadata you enter. Redemption codes, gift-card numbers, and PINs are stored separately in your device's secure storage. Images you select and OCR text derived from them stay in app-private storage and are not uploaded by Checkout Rewards.
- Store and location lookup: when you request a nearby-store answer, your current coordinates are sent through our service to Google Places. When you search, the search text and any location you chose to share are sent for that lookup. Lookup inputs and results may be cached in service memory for up to five minutes to improve reliability; Checkout Rewards does not create a server-side location-history timeline.
- Checkout reminders: if you separately opt in, background location samples are used to recognize when you arrive at a likely merchant. On Android this runs in a foreground service with a visible persistent notification. The device temporarily keeps an account-scoped candidate merchant identifier and timestamp and, after a reminder, a merchant identifier and cooldown timestamp. Entries older than 24 hours are discarded the next time reminder state is read. Turning reminders off, signing out, or switching accounts clears the relevant active state.
- Support and diagnostic information: information you voluntarily include in a support email, plus standard infrastructure logs used to operate and secure the service, such as request time, network address, status, and error category. We do not use your data for advertising or cross-app tracking.
How we use information
- Authenticate accounts, synchronize Wallet selections, resolve merchants, and produce reward recommendations.
- Show locally saved coupons and gift cards before recommending a card for the remaining purchase.
- Deliver an optional local checkout reminder after you grant notifications and background-location access.
- Respond to support and deletion requests, maintain security, troubleshoot failures, and comply with applicable law.
Services we use
Checkout Rewards uses Supabase for authentication and Wallet data, Apple and Google for optional sign-in, Vercel to operate the application service, and Google Places to resolve merchants. These providers process the limited data needed to provide their service under their own terms and privacy practices. Google Places credentials and server credentials are not included in the mobile app. Checkout Rewards does not send coupon screenshots, OCR text, redemption codes, gift-card numbers, or PINs to these services.
Your choices
- Location is optional. You can use merchant search instead of current location.
- Checkout reminders are off until you explicitly enable them. You can turn them off in Profile or iOS Settings at any time.
- You can remove saved coupons and gift cards. Removal deletes their app-private image and secure redemption secret.
- You can delete your account from Profile or follow the public account-deletion instructions. Account deletion removes server-side account and Wallet data; completing it in the app also clears that account's local vault data on that device.
Retention, backups, and security
We retain server-side account and Wallet data while your account is active and remove it when account deletion completes, except for limited records required for security, legal compliance, or documenting the request. Lookup cache entries expire after no more than five minutes. Reminder candidate and cooldown entries older than 24 hours are discarded the next time reminder state is read; disabling reminders, signing out, switching accounts, or deleting the account clears the relevant active state. Your device retains local coupon and gift-card data until you remove it or complete account deletion in the app. Removing the app ordinarily erases its app-private metadata and images, but platform secure storage can persist across an uninstall on some devices, so uninstall alone is not our device-data deletion method. Android app backup is disabled; iOS may include eligible app-private metadata or images in a platform-managed backup according to your device settings. Redeemable secrets use non-migrating, device-only platform secure storage.
We use encrypted transport, platform secure storage for redeemable secrets, and row-level access controls for Wallet data. No system can be guaranteed completely secure, so do not send sensitive codes or payment credentials in support messages.
Sale, sharing, and tracking
We do not sell personal information, use it for behavioral advertising, or track you across other companies' apps and websites. We disclose data to the service providers described above only as needed to operate Checkout Rewards or when required by law.
Children
Checkout Rewards is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
We may update this policy when the service changes and will post the revised effective date here. For privacy questions or requests, contact hello@checkoutrewards.app.