FreshRewardsOnPointStack
HomeTermsSupport
Privacy

FreshRewards pilot privacy notice

Pilot draft for legal and Information Officer review. Do not publish as the final production notice until approved.

Last updated 12 August 2026. This notice explains the information used to operate one FreshRewards membership across participating FreshCloud stores in South Africa.

Information collectedHow it is usedSharingRetentionYour choicesSecurityContact

Information we collect

Membership information includes a global customer ID, verified email address, date of birth, optional South African mobile number, device sessions, consent choices, favourites and support activity. Programme records include points ledger events, eligible transaction references, earning and redeeming locations, reward claims, redemptions, expiry and settlement evidence. We also collect limited security, delivery and diagnostic data needed to protect and operate the service.

How we use information

  • Verify and recover your membership using single-use email codes.
  • Calculate, display and protect points and reward claims.
  • Validate online redemptions and handle returns, reversals and expiry.
  • Send operational messages and, only where permitted, channel-specific marketing.
  • Prevent abuse, investigate support cases and maintain an auditable programme.

Who receives information

Participating stores receive only the information needed to identify a membership, award a finalized sale or validate a reward at checkout. Authorised programme, support, finance and platform staff receive role-limited access. Approved hosting, email, push-notification, telemetry and app-platform providers may process information under service and security controls. FreshRewards does not sell customer information.

Retention and account deletion

When an account is deleted, sessions and consent are revoked, live claims are released, remaining points are forfeited, and eligible personal information is anonymised. Pseudonymised ledger, fraud, audit and statutory records may be retained where needed to preserve financial integrity or meet legal obligations. Final retention periods require legal approval before production launch.

Your choices and rights

You can review and change push, email, SMS and marketing choices independently in the app. Operational messages about security, claims, expiry or account changes are separate. Subject to applicable law, you may request access, correction, objection, restriction or deletion through the published support channel. Email is the recovery identity; a customer-supplied mobile number does not authorise recovery, merging, redemption or sensitive changes.

Security

FreshRewards uses short-lived one-time codes, revocable device sessions, role-based staff access, independent approval for sensitive programme changes, site-specific credentials, immutable value events and short-lived single-use redemption proof. No internet service can promise absolute security; suspected incidents are handled through the programme response process.

Contact and complaints

The production operator identity, Information Officer contact and verified support email must be inserted after legal and deliverability approval. Until then, use the attended pilot support process supplied with your test invitation.

FreshRewardsOnPointStack
PrivacyTermsSupport

© FreshRewards.