Privacy Policy
Plain language, because that's the whole point. Rewardtree is built so businesses can run loyalty without harvesting their customers — here is exactly what we collect, why, and what we will never do with it.
Effective 29 August 2026 · NK Tech Pty Ltd (trading as Rewardtree), Sydney, Australia · [email protected]
The short version
- We collect the minimum needed to run a loyalty card: your mobile number, first name, and your stamps and rewards.
- Marketing is opt-in only — the consent box is never pre-ticked, and you can change your mind any time at rewardtr.ee/manage.
- A business only ever sees the activity of its own members at its own venues — never where else you shop.
- No ad networks, no analytics brokers, no selling or renting data. Ever.
Who we are
Rewardtree is operated by NK Tech Pty Ltd, an Australian company based in Sydney. We provide wallet-based loyalty programs to local businesses ("merchants"). When you join a merchant's program, the merchant runs the program and we process your information on their behalf and as the platform. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect — customers (card holders)
Mobile number: your account identifier, verified by SMS code when you join. One number, one membership — your cards and balances live with your number, not a device.
First name: shown to staff when you scan, and on your pass.
Email (optional): if you add one, including one you add later from the app's profile page, it's used for receipts of your own activity and shared with the business whose program you joined.
Date of birth (optional): only so a business can send you a birthday offer — and only if you've opted into marketing.
Loyalty activity: stamps, points, redemptions and rewards at each business you're a member of. This ledger is append-only — history is corrected by adjustment, never silently rewritten.
Location (optional, app only): if you use the Rewardtree app and allow location, we use it on-device requests to show nearby venues. Say no and you can search by suburb instead — nothing breaks.
Device identifiers: standard technical identifiers used to deliver passes and prevent fraud.
If a business brings its existing list: sometimes a business you already gave your details to (an older loyalty system, a booking list) moves its program to Rewardtree and uploads those details — name, mobile, email, birthday, existing balance. We use them only to offer you your card: your consent settings start off, and if you ignore the invitation we don't market to you.
We do not collect payment card details from customers, and the QR scan at the counter reads your code on the staff device — it doesn't photograph you or store images.
What we collect — businesses and their staff
Business name, ABN, venue addresses and trading hours; staff names, emails and roles for dashboard and scanner access; a scan-time GPS reading from the staff device (to confirm scans happen at the venue — a fraud control, softly flagged, never used to embarrass a customer); and billing details for paid plans, handled by Stripe — we never see or store card numbers.
How we use it
- Running the program: issuing passes, recording stamps, unlocking and redeeming rewards, updating your pass in Apple or Google Wallet.
- Service messages: verification codes and transactional pass updates. These are part of the product, not marketing.
- Marketing — only with your express consent: when you join, the consent checkbox is unticked by default and plainly worded. If you tick it, the business you joined can send you offers; you can withdraw consent any time and your consent status travels with any export of the data.
- Fraud prevention and security: device signals, rate limits and geofence checks that keep programs honest.
- Aggregate insights: merchants see statistics about their own program. Any network-level benchmarks are computed platform-side from aggregates over at least ten businesses with no single business dominating — never from anything that identifies a person.
The boundary that matters
Each business sees only its own members' activity at its own venues. Your full picture — every card you hold across every business — exists only platform-side and in your own hands (your app and your passes). We do not tell one business where else you shop.
Who we share with
Only service providers needed to run Rewardtree, under contract, for the purposes above:
- Cloud hosting — our servers and databases, in Australian data centres.
- Apple & Google — delivering your pass to Apple Wallet / Google Wallet.
- Twilio — sending SMS verification codes.
- Stripe — payments for business subscriptions.
- Cloudflare — network security in front of our servers, and its Turnstile check on our business sign-up form, which tells bots from people without a puzzle (see Cloudflare's Turnstile Privacy Addendum).
- Anthropic — AI features: suggesting how a spreadsheet's columns map when a business imports its existing member list (only the column headers and value patterns are processed — never the rows themselves), and drafting campaign and insight text from a business's own aggregate statistics. Processed under contract, never used to train AI models.
- Address search (OpenStreetMap) — when a business owner types their shop's street address in the dashboard, our servers send what they type to Photon (open-source address search run by komoot) to suggest matching addresses as they type, and to Nominatim (run by the OpenStreetMap Foundation) to find the address on the map when they save. Only the shop address a business owner types is sent — never customer information, and never anything from the owner's own device.
Our servers and databases are hosted in Australia, in local data centres. Some providers above process limited data overseas, mainly in the United States: Twilio (your number, to deliver SMS), Apple and Google (pass content), Stripe (business billing), Anthropic (column patterns and aggregate statistics), Cloudflare (network traffic). The address search services (Photon and Nominatim) process the shop addresses that business owners type on servers in Europe. We take reasonable steps to make sure they handle it consistently with the Australian Privacy Principles.
A business can also connect its own tools (for example Zapier, a mailing platform, or its booking system) to receive events about its own program — those tools are chosen by, and act for, that business under its own privacy obligations.
We do not sell, rent or trade personal information. We don't run ads and we don't share data with ad networks or data brokers. We disclose information beyond this list only if the law requires it.
Keeping and deleting your data
We keep information while your membership or account is active. Customers can leave any program, or delete their account entirely, from rewardtr.ee/manage, the app, or by emailing [email protected] — we action requests within 30 days. Businesses can export their member list (CSV, every plan) and close their account at any time — no lock-in is a founding promise. When you delete, we remove personal information from live systems within 30 days, keeping only what the law obliges us to retain (for example, billing records). Our loyalty ledger is append-only — that's how balances stay trustworthy — so transaction records themselves are kept, but after deletion they no longer link to you: your number, name and details are scrubbed and the records point at an anonymous placeholder.
Security
Traffic is encrypted (TLS), access is role-based and audited, loyalty codes are one-time and short-lived, and the earn ledger is append-only. If a data breach is likely to cause serious harm we will notify affected people and the OAIC under the Notifiable Data Breaches scheme.
Children
Rewardtree isn't directed at children. You need to be at least 16 — or have a parent or guardian's OK — to join a program, and marketing consent only counts from people who can give it. If we learn we hold a young child's details, we'll delete them.
Your rights
You can ask us for access to the personal information we hold about you, ask us to correct it, or complain about how it's been handled: [email protected]. We respond within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Changes
If this policy changes, the new version appears here with a new effective date. A material change to how we use personal information will be flagged to account holders before it takes effect.