Privacy Policy
Last Updated: April 3, 2026
Effective Date: April 3, 2026
Sopoints ("we," "us," or "our") operates the Sopoints platform, which includes the Sopoints Customer mobile application, the Sopoints Merchant mobile application, the Sopoints Merchant web dashboard, and the sopoints.com website (collectively, the "Services"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you access or use any of our Services.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of the Services.
1. Scope
This Privacy Policy applies to all Sopoints products and services, including:
- The Sopoints Customer mobile app (iOS and Android)
- The Sopoints Merchant mobile app (iOS and Android)
- The Sopoints Merchant web dashboard
- The Sopoints Customer web application
- The sopoints.com website
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Name, email address, password, and optionally phone number.
- Profile Information: Profile photo, date of birth, and shipping address (for prize or reward fulfillment).
- Business Information (Merchants): Business name, category, description, address, logo, banner images, support contact details, and website URL.
- Payment Information: Payment card details are collected and processed directly by our PCI-DSS compliant payment processor. We do not store full card numbers on our servers. We retain only a tokenized reference, card brand, last four digits, and expiration date for display purposes.
- Uploaded Content: Photos, images, and documents you upload to the Services (e.g., business logos, reward images, promotional materials).
- Communications: Messages and attachments you submit through our in-app support system or via email.
2.2 Information Collected Automatically
When you access or use our Services, we may automatically collect:
- Device Information: Device type, operating system, and device identifiers used for push notification delivery.
- Log Data: IP address, browser type, access times, pages viewed, and referring URLs when you use our web-based Services. Log data is used for security monitoring and is retained on a rotating basis.
- Location Data: With your explicit permission, the Customer app collects precise location data to display nearby merchants and deals. Location is accessed only while the app is actively in use. You may revoke location permission at any time through your device settings.
- Usage Data: Interactions with the Services, including transactions, QR code scans, reward redemptions, and feature usage.
- App Performance Data: Application version and update status for delivering over-the-air updates to mobile applications.
2.3 Information from Third-Party Sign-In
If you choose to sign in using a third-party identity provider (such as Google or Apple), we receive your name and email address (or a private relay email, if applicable) from that provider. We do not receive or store your third-party account password.
2.4 Cookies and Local Storage
Our web-based Services use cookies and browser storage technologies:
- Authentication Cookies: Strictly necessary, HTTP-only, secure cookies that contain encrypted session tokens. These are essential for you to remain signed in.
- Local Storage: Used to store user preferences (such as language and theme settings) and session state on web applications.
- Offline Storage: Our progressive web application may use browser-based offline storage to cache content for improved performance and offline access.
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. All cookies used are strictly necessary for the operation of the Services.
2.5 Financial and Transaction Data
- Loyalty point balances, earning and redemption history
- Transaction records including purchase amounts and timestamps
- Merchant financial data: pool account balances, settlement records, billing and subscription information
2.6 Biometric Data
Our mobile applications support device biometric authentication (such as Face ID or Touch ID) for app lock functionality. All biometric processing occurs locally on your device through the operating system. Biometric data is never transmitted to or stored on our servers.
3. How We Use Your Information
3.1 Providing and Operating the Services
- Create, authenticate, and manage your account
- Process loyalty point transactions, rewards, and redemptions
- Display personalized content such as nearby merchants and relevant deals
- Process payments, subscriptions, and merchant settlements
- Facilitate point-of-sale operations via QR code and NFC
- Manage merchant locations, staff permissions, and customer relationships
- Operate platform features including games, referrals, achievements, and tier programs
- Support digital wallet pass integration
3.2 Communications
- Send transactional notifications (e.g., account verification, password resets, transaction confirmations, security alerts)
- Send promotional communications with your consent (e.g., marketing emails, campaign notifications)
- Deliver push notifications about account activity and relevant offers
- Send SMS messages for time-sensitive communications such as two-factor authentication
- Respond to your support inquiries
3.3 Analytics and Service Improvement
- Generate aggregated, anonymized analytics for merchants (e.g., customer engagement trends, transaction volumes)
- Monitor service performance, reliability, and uptime
- Deliver app updates and improvements
3.4 Security and Fraud Prevention
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Enforce rate limits and protect against automated attacks
- Enforce our Terms of Service
- Comply with applicable legal obligations
4. How We Share Your Information
We do not sell your personal information. We share your data only in the following limited circumstances:
4.1 Service Providers
We engage trusted third-party service providers to assist in operating our Services. These providers are contractually obligated to protect your data and may only use it for the purposes we specify:
- Payment Processing: Card payment data is processed by our PCI-DSS Level 1 compliant payment processor for billing, subscriptions, and merchant payouts.
- Push Notification Delivery: Device tokens are shared with push notification infrastructure providers to deliver notifications to your device.
- Email Delivery: Your email address and message content are shared with our email service provider for transactional and promotional communications.
- SMS Delivery: Your phone number is shared with our SMS service provider for time-sensitive notifications and two-factor authentication.
- Cloud Infrastructure: Your data is stored and processed on secure cloud infrastructure with industry-standard security certifications.
- App Update Services: Device platform and app version information is shared with our mobile update service to deliver over-the-air application updates.
- Identity Providers: Authentication tokens are exchanged with Google and Apple when you choose to sign in using their services.
4.2 Merchant-Customer Data Sharing
When you interact with a merchant on Sopoints (e.g., earn points, redeem rewards, or enroll in a loyalty program), that merchant may access:
- Your name and profile photo
- Your email address and phone number (if provided)
- Your loyalty point balance and transaction history with that specific merchant only
- Your tier status and lifetime loyalty activity with that merchant
Merchants do not have access to your data from other merchants, your precise location, your financial information, or any data unrelated to their loyalty program.
4.3 Merchant Integrations
Merchants may configure integrations (such as webhooks or point-of-sale connections) that receive event notifications related to their own business operations. These integrations contain only merchant-specific data and are secured with cryptographic signatures.
4.4 Legal and Compliance
We may disclose your information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request
- Protect the rights, property, or safety of Sopoints, our users, or the public
- Detect, prevent, or address fraud, security issues, or technical problems
- Enforce our Terms of Service or other agreements
4.5 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our Services before your information becomes subject to a different privacy policy.
5. Data Security
We implement industry-standard technical and organizational measures to protect your information:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are securely hashed using modern cryptographic algorithms
- Authentication tokens on mobile devices are stored in platform-provided secure storage (iOS Keychain, Android Keystore)
- Web sessions use HTTP-only, secure cookies with appropriate SameSite policies
- Cross-site request forgery (CSRF) protection is enforced on all endpoints
- API rate limiting and abuse detection are in place
- Sensitive data in server logs is automatically sanitized
- Access to production systems is restricted and monitored
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law:
- Account Data: Retained while your account is active and for 30 days following a deletion request.
- Transaction Records: Retained while your account is active for loyalty program accuracy and legal compliance.
- Session Data: Expired sessions are automatically purged on a daily basis.
- Temporary Tokens: Password reset and email verification tokens are automatically deleted after use or upon expiration (24 hours and 7 days, respectively).
- Device Records: Push notification tokens are removed upon logout or account deletion. Device registration records are retained for up to 90 days for fraud prevention.
- Server Logs: Retained on a rotating basis for security monitoring and troubleshooting.
- Support Tickets: Retained for the lifetime of your account for reference purposes.
7. Your Rights and Choices
7.1 Access and Portability
You may request a copy of your personal data in a portable, machine-readable format by contacting us at support@sopoints.com.
7.2 Correction
You may update or correct your personal information at any time through the account settings in your app or web dashboard.
7.3 Account and Data Deletion
You have the right to request deletion of your account and all associated personal data at any time:
- Sopoints Customer App: Profile > Security > Delete Account
- Sopoints Merchant App: Settings > Security > Delete Account
- By Email: support@sopoints.com
Upon request, your account will be scheduled for permanent deletion within 30 days. During this grace period, you may contact us to cancel the deletion. After 30 days, all personal data associated with your account will be permanently and irreversibly removed, including:
- Your profile and personal information
- Wallet balances and loyalty points
- Transaction and ledger history
- Notification preferences and device registrations
- Achievement, referral, and tier records
- All active sessions and credentials
You will receive a confirmation email when your deletion is scheduled and when it has been completed.
7.4 Communication Preferences
- Push Notifications: Manage through your device's notification settings at any time.
- Marketing Emails: Unsubscribe using the link provided in any promotional email. Transactional emails related to your account security and activity cannot be opted out of while your account remains active.
- SMS: Opt out by contacting support@sopoints.com.
7.5 Permissions
You may revoke any device permissions (location, camera, photo library, NFC) at any time through your device's settings. Revoking certain permissions may limit specific features but will not affect the core functionality of the Services.
8. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have inadvertently collected information from a child under 18, we will promptly take steps to delete it. If you believe a child may have provided us with personal information, please contact us at support@sopoints.com.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including Canada and the United States. These countries may have data protection laws that differ from those of your jurisdiction. We take appropriate safeguards to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
10. Region-Specific Rights
10.1 Canadian Residents (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to access, correct, and withdraw consent for the use of your personal information, subject to legal or contractual restrictions.
10.2 California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act and the California Privacy Rights Act, California residents have the right to:
- Know what personal information is collected, used, and shared
- Request deletion of personal information
- Opt out of the sale or sharing of personal information (we do not sell or share your data for advertising purposes)
- Non-discrimination for exercising privacy rights
10.3 European Residents (GDPR)
Under the General Data Protection Regulation, individuals in the European Economic Area have the right to access, rectify, erase, restrict processing, data portability, and objection. Our legal bases for processing include: contract performance, legitimate interests, consent, and legal obligations.
To exercise any of these rights, please contact us at support@sopoints.com.
11. Third-Party Links
Our Services may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of such third parties and encourage you to review their privacy policies before providing any personal information.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, or legal requirements. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where appropriate, by providing additional notice through the Services or via email. Your continued use of the Services following any changes constitutes your acceptance of the revised Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We will respond to all privacy-related inquiries within 30 days.