Privacy Policy
Rewards Card Wallet
Effective date: February 22, 2026
Rewards Card Wallet ("the App", "we", "us") is developed by eBoxr. This Privacy Policy describes how we collect, use, and protect your information when you use our iOS application. The App is designed for storing loyalty and rewards cards only — it is not a payment application and cannot be used to make financial transactions.
1. Information We Collect
Account Information
When you create an account, we collect:
- Email address (via email sign-up or Apple Sign In)
- Password (hashed and stored securely; we never have access to your plaintext password)
Profile Information (Optional)
- Display name
- Profile picture
Card Data
When you add cards to the App, we store:
- Card name, description, and color
- Card number (encrypted with AES-256-GCM; only the last 4 digits are stored unencrypted for display)
- Barcode type and value (encrypted)
- Expiration date
- Card status and preferences
Purchase Information
If you purchase the Pro upgrade, we store your Apple transaction ID and purchase date to verify your purchase status. We do not have access to your payment details — all payments are processed by Apple.
2. How We Use Your Information
We use your information solely to:
- Provide and maintain the App's functionality
- Store and display your cards securely
- Generate Apple Wallet passes for your cards
- Verify your purchase status
- Authenticate your identity
3. Data Storage and Security
Your data is stored on secure servers provided by Supabase, our backend infrastructure provider. Card numbers and barcode data are encrypted on your device before being transmitted to the server. Encryption keys are stored in your device's Keychain.
We also support two-factor authentication (TOTP) for additional account security.
4. Third-Party Services
The App uses the following third-party services:
- Supabase — database, authentication, and file storage (supabase.com/privacy)
- Clearbit Logo API — to display store logos based on store name. No personal data is shared with Clearbit.
- Apple Services — Sign in with Apple, Apple Wallet (PassKit), and In-App Purchases (StoreKit)
5. What We Do Not Collect
- We do not use analytics or tracking SDKs
- We do not collect device advertising identifiers
- We do not collect location data
- We do not sell, rent, or share your personal data with third parties
6. Camera and Photo Library
The App requests access to your camera to scan barcodes. Images are processed locally on your device and are not transmitted to any server. Photo library access is used only if you choose to set a profile picture.
7. Data Retention and Deletion
You can delete your account at any time from within the App. Deleting your account permanently removes all of your data, including your cards, profile, and subscription information, from our servers.
8. Children's Privacy
The App is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the updated policy within the App. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy, please contact us at:
support@eboxr.com