Privacy Policy
1. WHAT WE COLLECT — Identity (name, DOB, address), contact (email, phone), authentication (password hash), payment-processing tokens (we never store full card numbers — Stripe handles them), in-app messages, AI Concierge chat transcripts, IP addresses, user-agent strings, and consent timestamps. For users 13–17, we also collect parent/guardian email and consent records.
2. WHY WE COLLECT IT (lawful bases) — Contract performance (deliver your membership benefits), legitimate interest (fraud detection, audit logs, abuse prevention), legal obligation (tax records, COPPA verification), and consent (marketing emails, optional analytics). EU users can withdraw consent at any time.
3. RETENTION — By default, account data, messages, and AI chat transcripts are retained indefinitely for safety, audit, and dispute-resolution purposes. EXCEPTION: you may request deletion at any time via the in-app Privacy Center or by emailing privacy@adnrewards.com. We honor verified deletion requests within 30 days (45 in California per CPRA, 30 in EU per GDPR). Reported/flagged messages and payment records may be retained longer where required by law.
4. VENDORS WE SHARE DATA WITH — Stripe (payment processing), MongoDB Atlas (encrypted database), Resend (transactional email), Emergent (LLM-powered Concierge), Cloudflare (DNS + DDoS), Leaflet/OpenStreetMap (maps). Each vendor signs a Data Processing Agreement (DPA) restricting them to processing only as instructed. We do not sell your personal data.
5. YOUR RIGHTS — Right to access, right to correct, right to delete, right to portability (download your data as JSON), right to object, right to restrict processing, right to withdraw consent. California residents: right to know, right to opt out of sale (we don't sell), right to limit sensitive-PI use. Submit any request from the Privacy Center in your dashboard.
6. INTERNATIONAL TRANSFERS — Data is stored in the United States. EU/UK transfers rely on Standard Contractual Clauses (SCCs). Brazilian users are protected per LGPD. Canadian users per PIPEDA.
7. COOKIES — We use strictly-necessary cookies for authentication, and (with your consent) analytics cookies to improve the product. EU and California visitors see a consent banner on first visit. You can change preferences anytime in the Privacy Center.
8. CHILDREN — We do not knowingly collect personal information from children under 13. If we discover such data, we delete it. Users 13–17 require verified parental consent before account activation.
9. SECURITY — Passwords are bcrypt-hashed, transport is HTTPS-only, MongoDB Atlas storage is encrypted at rest, admin actions are audit-logged. We notify affected users and regulators within 72 hours of any confirmed data breach.
10. CONTACT — Data Protection Officer: privacy@adnrewards.com
This page is a plain‑language summary intended for transparency. Final binding terms will be presented at signup and may be updated. Contact support for the latest version.