Privacy Policy
Last updated August 2026
This policy explains what data Smiles Rewards ("we", "us") collects when a merchant ("you", "merchant") uses our loyalty and customer engagement platform, why we collect it, and how it's handled. It covers both the merchant accounts we work with directly and the end-customer data those accounts contain.
What we collect
To operate the loyalty platform, we read and store:
- Customer records synced from a merchant's connected systems (currently Odoo and Shopify) — name, email, and any loyalty-relevant identifiers those systems already hold.
- Loyalty and purchase data — points balances, tier status, and purchase events, mirrored from wherever they already live in the merchant's systems.
- Engagement records — which automated messages (points expiring, win-back, tier reached) were sent, and when, so the same customer isn't messaged twice for the same event.
- Merchant account and admin data — the credentials and configuration a merchant provides to connect their Odoo or Shopify account, and basic contact details for anyone submitting the demo-request form on our marketing site.
We don't ask end customers to sign up with us directly — we mirror data that already exists in a merchant's own systems rather than collecting it ourselves.
How we use it
Data is used solely to operate the platform for the merchant it belongs to: resolving a customer to one record across channels, evaluating whether a trigger (points expiring, inactivity, tier change) applies, and sending the resulting message. We don't use merchant or customer data to train models, build cross-merchant profiles, or for any purpose unrelated to running the platform a merchant has asked us to run.
No cross-merchant pooling
Every customer record is scoped to the merchant it belongs to. There is no shared or pooled customer graph across merchants on the platform — a customer record for one merchant is never joined, matched, or shared with another merchant's data, even if the same person shops at both.
Sharing
We don't sell customer or merchant data. Data is shared only with the infrastructure providers necessary to run the service — our hosting provider and our transactional email provider (Resend) for delivering the messages a merchant's triggers generate — and only to the extent needed for them to perform that function.
Data retention
We retain customer and loyalty data for as long as a merchant's account is active. If a merchant stops using the platform, we retain their data only as long as reasonably needed to wind down the account or as required by law, then delete it. Merchants can request deletion at any time by contacting us.
Security
See our Security page for how we protect data in transit and at rest, and how to report a security concern.
Your rights
If you're an end customer of one of our merchants and want to know what data we hold about you, that request should go to the merchant you're a customer of — they control that relationship, and we act on their behalf. Merchants themselves can contact us directly at any time to access, correct, or delete the data associated with their account.
Changes to this policy
We'll update the date at the top of this page when this policy changes. Since we're still in a pilot stage with a small number of merchants, we'll also reach out directly about any change that materially affects how existing merchant data is handled.
Contact
Questions about this policy or a request related to your data: [email protected].