RequityX

Privacy Policy

Effective September 2026 — pilot programme

RequityX is currently a small, invitation-based pilot. This policy describes what we actually collect and do today, in plain terms. It has not yet been reviewed by legal counsel and will be updated before the pilot opens beyond its current participants.

Who this covers

This policy applies to everyone who uses RequityX: members earning cash back, businesses recording visits and paying referral fees, and the operators who run the pilot.

What we collect

Account information.Name, email address, and a hashed password (or, if you sign in with Google, your Google account’s name and email — we never see or store your Google password). If you enroll a passkey to use the wallet, we store its public key and device metadata, never anything that could be used to impersonate your device.

Member details. Phone number and — entirely optional, self-reported, and never verified — a mailing address.

Business details. Business name, contact name and phone, business address, and the referral rate a business has chosen or been assigned.

Visit and credit records. Every visit a participating business records — the date and amount — and the referral credit it generates. This is the core of the product and is retained as long as your account exists, as an append-only history: a correction never erases what it corrects, it only supersedes it.

Bank-linked wallet data (optional feature). If you choose to connect a bank account so purchases at participating businesses are recorded automatically, our banking data partner (Plaid) shares with us: the connected institution’s name, the account’s nickname, at most the last four digits of the account number, and individual purchase records (date, amount, and merchant name) for purchases at businesses in the RequityX network. We never receive or store your full account number, routing number, or online banking credentials. A purchase at a business outside the network is matched against our business list in memory and discarded immediately — it is never written to our database at all.

Payment information. Businesses are billed through Stripe, our payment processor. We do not store card numbers or bank details for billing — Stripe does, under its own privacy policy.

How we use it

To calculate the cash back a visit earns, pay it out to the member, bill participating businesses for the referral fees they owe, let a business look up a customer at the counter, and let an operator review, correct, or reverse a visit when something goes wrong. We do not sell personal information, and we do not use it for advertising.

Who we share it with

  • Stripe — payment processing and invoicing for participating businesses.
  • Plaid — bank account connection and transaction data, only for members who opt into the wallet feature.
  • Resend — sends the transactional emails the platform relies on (invitations, account verification, password reset). It sees the recipient address and the email content; it does not see anything else in your account.
  • Google— if you choose “Sign in with Google,” Google authenticates you and shares your name and email with us. We do not receive your Google password, contacts, or any other Google account data.
  • Our hosting and database providers (Vercel and Supabase) — process data on our behalf to run the application; they do not use it for their own purposes.

We do not otherwise share personal information with third parties.

How we protect it

Every table in our database enforces row-level access control independent of the application code, so a bug in one layer does not by itself expose another member’s or business’s data. All traffic is encrypted in transit. A bank credential from the wallet feature is sealed by our banking data partner before it ever reaches our servers — nothing in our systems can read it. We keep an audit trail of every correction an operator or business makes to a record.

Your choices

The wallet (bank-linking) feature is entirely optional and can be disconnected at any time from your account, which also revokes our access to that bank connection. You can delete your account yourself, from Profile on the website or in the app: this removes your sign-in, name, phone, address, savings goals and every bank connection (including at the bank-data provider), and keeps your past visits in the businesses’ records without your name, because their invoices depend on them. Your available cash back is paid to your linked bank account before the deletion; cash back a business has not yet paid, or available cash back with no bank account to send it to, is forfeited. You can also ask us to access, correct, or delete your personal information by contacting us at the address below — for a pilot this small, that request reaches a real person directly. [Legal counsel: confirm any jurisdiction-specific rights this section should name explicitly, e.g. CCPA/GDPR, once the pilot’s user base is known.]

Retention

We keep account and visit records for as long as your account is active and for a reasonable period after, to support the referral history and tax/accounting records the platform’s businesses rely on. When you delete your account, what is personal goes at once (see “Your choices”); the visit and credit records stay, with no name on them. [Legal counsel: set a specific retention period for those records.]

Changes to this policy

We’ll update the effective date above when this policy changes, and — for a change that meaningfully affects how your data is used — tell participants directly rather than only updating this page.

Contact

Questions about this policy or your data: [contact email — e.g. privacy@requityx.com, once that address is confirmed and monitored].