Privacy Policy
RewardArchitect (rewardarchitect.com)
Effective Date: Aug 1, 2026
Last Updated: Aug 1, 2026
This Privacy Policy describes how RewardArchitect LLC (“RewardArchitect,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the RewardArchitect website at rewardarchitect.com and the RewardArchitect mobile applications for iOS and Android (collectively, the “Service”).
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
1. Who We Are
RewardArchitect is a credit card benefit and rewards optimization tool. It helps you track the benefits, sign-up bonuses, and annual value of credit cards you already hold, based on information you enter yourself.
Data Controller:
RewardArchitect LLC
120 Jefferson Ave, 12018 Miami Beach, FL 33139
Email: info@rewardarchitect.com
2. Important: What RewardArchitect Does NOT Collect
Because transparency matters most in a financial-adjacent product, we state this first:
- We never collect, request, or store credit card numbers, CVVs, expiration dates, or full account numbers for the cards you track in the Service. You identify cards by product name only (e.g., “Chase Sapphire Preferred”).
- We do not connect to your bank or card accounts. The Service does not use account aggregation services (such as Plaid, Finicity, or Yodlee) and never asks for your online banking credentials. All spending and benefit-usage data in the Service is entered manually by you.
- We do not collect precise geolocation, contacts, photos, microphone, camera, or health data.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The Service contains no third-party advertising.
- We do not use third-party advertising or tracking SDKs in our mobile applications.
3. Information We Collect
3.1 Information You Provide Directly
- Account information: Email address and password (passwords are stored only in salted, hashed form; we cannot read them). Optionally, a display name.
- Card portfolio data: The credit card products you choose to track (by product name), the dates you opened or plan to close them, and annual fees.
- Benefit and spending data you enter: Benefit usage you log (e.g., “used airline credit”), spending amounts you record for optimization or sign-up-bonus tracking, lounge visits you log, and notes you attach. These are self-reported figures you type in; they are not drawn from any financial institution.
- Communications: If you contact us for support, we receive the contents of your message and your email address.
3.2 Information Collected Automatically
- Log and device data: When you use the Service, our servers automatically record standard technical information: IP address, browser or device type, operating system, app version, pages or screens accessed, and timestamps. We use this for security, debugging, and to operate the Service.
- Cookies and similar technologies: The website uses strictly necessary cookies to keep you signed in and maintain session security. We do not currently use third-party analytics or advertising cookies. If that changes, we will update this Policy and, where required, request your consent.
3.3 Payment Information
Paid subscriptions purchased through our website are processed by Stripe, Inc. Your payment card details are transmitted directly to Stripe and are never stored on our servers. We receive from Stripe only limited information necessary to manage your subscription (e.g., subscription status, last four digits of your card, and billing country). Stripe’s handling of your payment data is governed by its own privacy policy, available at https://stripe.com/privacy.
If subscriptions are offered as in-app purchases in the future, those payments would be processed by Apple or Google under their respective privacy policies, and we would receive only transaction confirmations, not payment details.
4. How We Use Your Information
We use the information described above to:
- Create and maintain your account and authenticate you;
- Provide the core features of the Service — benefit tracking, spend optimization, sign-up bonus and retention tracking, lounge value analysis, and annual card-value reports — all of which operate on data you entered;
- Process and manage your subscription (via Stripe);
- Send transactional and service communications, such as password resets, subscription receipts, benefit-deadline or bonus-deadline reminders you have enabled, and material changes to the Service or this Policy;
- Respond to your support requests;
- Monitor, secure, and debug the Service, including detecting fraud, abuse, and unauthorized access;
- Comply with legal obligations.
We do not use your personal information for third-party advertising, and we do not use the financial figures you enter for any purpose other than providing the Service to you.
Legal bases (EEA/UK users): Where the GDPR or UK GDPR applies, we process your data (a) to perform our contract with you (providing the Service you signed up for); (b) for our legitimate interests in securing and improving the Service, balanced against your rights; (c) with your consent, where required (e.g., optional marketing emails); and (d) to comply with legal obligations.
5. How We Share Information
We share personal information only in the following limited circumstances:
- Service providers: With vendors that perform services on our behalf and are bound to use your data only for that purpose — currently our cloud hosting/infrastructure provider(s) and Stripe (payments).
- Legal compliance and protection: If required by law, subpoena, or other legal process, or where necessary to protect the rights, safety, or property of RewardArchitect, our users, or others.
- Business transfers: If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction; we will notify you before your information becomes subject to a different privacy policy.
- With your direction: If you explicitly ask us to share something.
We do not sell personal information, and we have not sold personal information in the preceding 12 months. We do not “share” personal information for cross-context behavioral advertising as those terms are defined under California law.
6. Data Retention
We retain your account and the data you have entered for as long as your account is active. If you delete your account, we delete your personal information and entered data within 30 days, except for limited records we are required to retain (e.g., payment/tax records held by or via Stripe, security logs) or data retained in routine encrypted backups, which are overwritten on a rolling basis within 90 days. Aggregated or de-identified data that can no longer reasonably be linked to you may be retained.
7. Account and Data Deletion
You can delete your account and all associated data at any time:
- In the app / on the website: Settings → Account → Delete Account; or
- On the web without the app: Visit https://rewardarchitect.com/delete-account; or
- By email: Send a request to info@rewardarchitect.com from the email address on your account.
Deletion is permanent and cannot be undone. Subscription cancellation is handled through your Stripe billing portal (or the app store, for any in-app purchase).
8. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights: to access the personal information we hold about you, to correct inaccurate information, to delete your information, to receive a portable copy of it, to opt out of sale/sharing/targeted advertising (not applicable — we don’t do these), and to not be discriminated against for exercising your rights.
To exercise any right, use the in-app tools described above or email info@rewardarchitect.com. We will verify your request using the email address associated with your account and respond within the time required by applicable law (generally 45 days in the U.S., 30 days in the EEA/UK). You may use an authorized agent where the law permits; we will require proof of authorization.
8.1 California Residents (CCPA/CPRA)
In the last 12 months we collected the categories of personal information described in Section 3: identifiers (email, IP address), internet/network activity (log data), and financial-adjacent information you voluntarily entered (self-reported card products, spending, and benefit usage). We collected it from you directly and automatically from your device, for the purposes in Section 4, and disclosed it only to the service providers in Section 5. We do not sell or share personal information, we have no actual knowledge of selling or sharing the personal information of consumers under 16, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. California residents may exercise their rights via the methods above; because we do not sell or share data, no opt-out link is required, but we honor the Global Privacy Control (GPC) signal as an opt-out where applicable.
8.2 Other U.S. State Privacy Laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws may exercise the rights listed above using the same contact methods. If we deny a request, you may appeal by replying to our decision email with “Appeal” in the subject line.
8.3 EEA, UK, and Switzerland
You additionally have the right to object to processing based on legitimate interests, to restrict processing, to withdraw consent at any time (without affecting prior processing), and to lodge a complaint with your local supervisory authority. Our processing is described in Sections 3–5; we do not engage in automated decision-making that produces legal or similarly significant effects.
9. International Data Transfers
RewardArchitect is operated from the United States, and your information is stored on servers located in the United States. If you use the Service from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction. For transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses with our service providers where required.
10. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information, including encryption of data in transit (TLS), password hashing, access controls, and hosting with reputable cloud infrastructure providers. Because you enter card products by name only and we hold no card numbers or bank credentials, the sensitivity of the data at risk is deliberately minimized by design. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and regulators as required by applicable law.
11. Children’s Privacy
The Service is a financial planning tool intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 years of age (and in no event under 13, or under 16 in the EEA/UK without parental consent). If we learn that we have collected personal information from a child, we will delete it promptly. If you believe a child has provided us information, contact info@rewardarchitect.com.
12. Do Not Track and Opt-Out Preference Signals
We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request where required by law. Because we do not track users across third-party websites or serve targeted advertising, browser “Do Not Track” signals do not change how the Service operates.
13. Push Notifications and Reminders
If you enable them, the mobile apps may send push notifications (e.g., benefit-expiration or bonus-deadline reminders). You can disable these at any time in your device settings or in the app. Notification tokens are used solely to deliver notifications you requested.
14. Third-Party Links
The Service may reference or link to credit card products, issuer websites, or airport lounge information. We are not affiliated with any card issuer, and those third-party sites have their own privacy policies. RewardArchitect provides informational tools only and does not provide financial advice.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes — especially any change to the categories of data we collect or how we share it — we will notify you by email or in-app notice before the change takes effect and update the “Last Updated” date above. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
16. Contact Us
Questions, concerns, or rights requests:
RewardArchitect LLC
120 Jefferson Ave, 12018 Miami Beach, FL 33139
Email: info@rewardarchitect.com
Web: https://rewardarchitect.com