Legal Document — Student & Vendor-Facing
Effective Date: July 29, 2026 · Last Updated: August 26, 2026
WeRewards ("we," "us," "our") is a loyalty rewards platform operated by Krish Chavan, an individual based in Pennsylvania. WeRewards is an independent service and is not affiliated with The Pennsylvania State University.
For privacy-related questions, contact us at: [email protected]
Signing in with Google does not by itself create a WeRewards account. After you choose your Google account we ask you to accept the Terms and this Policy, and your account is created only when you do. If you decline, the sign-in is discarded and nothing about you is kept.
Once you accept, we store:
Your Google profile photo URL is displayed in the app but is fetched directly from Google's servers and is not stored in our database.
Each time you earn or redeem points at a vendor, or move community points into a vendor balance, we record:
We also maintain your current point balance at each participating vendor and your community points balance (see Section 4.6 of the Terms of Service).
We compute a rolling 30-day engagement score that determines your earn multiplier tier. This score is derived from your transaction history and reflects:
This score is stored and updated automatically.
We generate temporary earn codes (6-digit) and redemption codes (4-digit) for your account. Redemption codes are single-use and expire 120 seconds after you generate them. Earn codes expire 5 minutes after they are issued; while you have the app open, your existing code is refreshed rather than replaced, so the same 6 digits may stay valid for as long as you keep the screen open. Both are automatically deleted after use or expiration.
If the app encounters an error, we may automatically record a crash report containing your user ID, the page you were on (path only — never the query string), the HTTP method and response status of the failed request, a technical error message and stack trace, your browser's user agent string, and a small amount of technical context about what the app was doing at the time. Error logs are retained for 90 days and then automatically deleted.
If you grant your browser's notification permission to WeRewards, your browser gives us a push subscription: an endpoint URL at your browser vendor's push service (Google, Apple, or Mozilla, depending on your device) plus two encryption keys. We store these against your user identifier so we can deliver notifications to that device, and delete them when you turn deal alerts off, when you revoke permission, or when the push service tells us the subscription is dead.
For each deal you are selected to receive, we record which deal it was, whether a message was sent, which way it was sent (push notification or email), and whether you opened it. We also keep a small counter per account (when you were last messaged, and how many messages you have had in the current day and week) purely to enforce the frequency limits in Section 7.4. These records are deleted about 30 days after the deal expires, and immediately if you delete your account.
Where we could not reach you with a push notification, a deal may instead be sent to the email address on your account (Section 7.4). Our email provider tells us whether each message was delivered, could not be delivered, or was reported as spam. If an address permanently cannot receive mail, or its owner reports one of our messages as spam or uses an unsubscribe link, we record that address on an internal suppression list so that nothing further is sent to it. That list holds the email address and the reason only.
When you accept the Terms and this Policy after signing in, we record that you did so: your user identifier, which version of the documents you accepted, the date and time, and — as evidence that the acceptance was genuine — your IP address and browser user agent at that moment.
This is the only place we record your IP address. We keep these records for as long as your account exists; they are deleted with it. If we revise the documents and ask you to accept again, that creates a new record rather than replacing the old one, so the history of what you agreed to and when stays intact.
WeRewards does not use tracking cookies, advertising cookies, or any third-party analytics. We do store the following in your browser's local storage:
All three are stored on your device rather than sent to us as a separate collection of data. You can clear them at any time through your browser's site-data settings.
Two features in WeRewards can use your location. Both ask your permission first, both work only while the app is open, and you can refuse or switch off either one without losing anything else.
The app includes a map of the spots you can earn points at. Opening that map does not involve your location at all: it shows the vendors' own addresses, which they gave us.
The map also has a "show my location" button. If you tap it, your browser will ask your permission to share your position, and you can say no. If you allow it:
Declining, or never tapping the button at all, leaves the map completely usable.
If you turn on Nearby spots (Account → Notifications), the app can let you know when you are next to a spot you have never earned points at. It is off until your browser grants us location permission, and we ask for that permission once, from a card that explains what it is for.
How it works, precisely:
This does not run in the background. Web apps cannot read your location when they are closed, and WeRewards does not try to. If the app is not open on your screen, nothing here is happening.
You can switch Nearby spots off at any time in Account → Notifications, or withdraw location permission in your device settings — the switch turns itself off when you do. Turning it off stops the alerts and no further records are made. It is separate from Deal alerts: switching one off does not affect the other.
You can claim points by photographing a paper receipt from a participating spot. Taking that photo is entirely up to you — you can always earn at the counter instead, and nothing here happens unless you tap submit.
When you submit a receipt photo:
A receipt photo may incidentally include whatever else is in the frame — the table, your hand, the card type printed on the receipt. Please photograph just the receipt. We never look for anything beyond the business name, the total, and the printed date and time.
Section 4.7 of the Terms of Service describes promotions that credit community points to your account for something other than a purchase. To run them we store:
An invitation necessarily connects two accounts, so this section states exactly what each side can see, and what we can see.
If you would rather not be part of this, simply do not use an invite link, and do not share your own code. Nothing about the rest of the Service depends on it.
| Purpose | Data Used |
|---|---|
| Create and manage your account | Name, email, user ID |
| Award and track loyalty points | User ID, transaction data, balance |
| Generate earn and redemption codes | User ID |
| Calculate your tier multiplier | Transaction history, engagement score |
| Show your activity history | Transaction data, vendor names, rewards |
| Provide data export on request | All data associated with your account |
| Detect and prevent fraud or abuse | User ID, transaction data, error logs |
| Award points for a receipt you photograph, and check the receipt is genuine and not already claimed | The receipt photo (read, then discarded — see Section 2.10), and the business, total, and printed date and time read from it |
| Debug and fix platform errors | Error logs, user agent, user ID |
| Operate platform analytics (admin-only) | Aggregated/anonymized transaction data |
| Select who receives a vendor's deal | User ID, transaction history at that vendor, balance at that vendor |
| Deliver deal notifications and cap their frequency | User ID, push subscription, email address, notification history |
| Credit a signup promotion | The email domain of your account and the date it was created |
| Credit an invite bonus, and decide when the person who invited you has qualified for theirs | Invite code, the link between the two accounts, and whether the invited account has earned points at any vendor |
| Run, audit, and detect abuse of a promotion (admin-only) | Bonus records, referral records including both accounts' email addresses |
We do not use your data for targeted advertising. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We use the following third-party services to operate WeRewards. Each service receives only the data necessary for its function.
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Supabase (supabase.com) |
Database, authentication, real-time updates | All stored user data; auth tokens | supabase.com/privacy |
| Google Identity / OAuth (google.com) |
User sign-in | Email, name, Google account ID | policies.google.com/privacy |
| Google User Content (googleusercontent.com) |
Displaying your Google profile photo | Your browser IP and user agent when the photo loads | policies.google.com/privacy |
| Google Fonts (fonts.googleapis.com) |
Typeface delivery | Your browser IP and user agent on page load | policies.google.com/privacy |
| Google Gemini API (generativelanguage.googleapis.com) |
Reading the printed text on a receipt you submit, and checking that it is a photograph of a real printed receipt rather than a screenshot or an edited image | The receipt photo itself, sent from our server at the moment you submit it and not stored by us. No name, email, or user identifier is sent with it. Google's terms for free-of-charge API use permit them to use submitted content to improve their models; paid API use does not | policies.google.com/privacy · ai.google.dev/gemini-api/terms |
| OpenStreetMap (openstreetmap.org, tile.openstreetmap.org) |
Map imagery, both the small map on each vendor card and the full-screen spots map | Your browser IP as each map tile loads. Your own location is never sent to them, including when you use the locate button (see Section 2.9) | osmfoundation.org/wiki/Privacy_Policy |
| Nominatim (nominatim.openstreetmap.org) |
Converting a vendor's street address into map coordinates | The vendor's business address only. Sent from our server, not your browser — no student data is involved | osmfoundation.org/wiki/Privacy_Policy |
| Apple Maps / Google Maps (maps.apple.com, google.com/maps) |
Turn-by-turn directions, only if you tap a vendor's address | The vendor's address and your browser IP, at the moment you tap. We do not send your location — the map provider may request it directly | apple.com/legal/privacy · policies.google.com/privacy |
| jsDelivr CDN (cdn.jsdelivr.net) |
Delivery of app libraries | Your browser IP and user agent on script load | jsdelivr.com/privacy-policy-jsdelivr-net |
| Heroku (heroku.com) |
Application server hosting | All data in transit through the app server | salesforce.com/company/privacy |
| Your browser's push service (Google FCM, Apple, or Mozilla, depending on your device) |
Delivering deal notifications, only if you grant notification permission | The notification text and the subscription endpoint your own browser issued. The message is encrypted with keys your browser generated, so the push service relays it without being able to read it | policies.google.com/privacy · apple.com/legal/privacy · mozilla.org/privacy |
| Resend (resend.com) |
Sending email: deal emails where a push notification could not reach you, and account email such as a password reset code you asked for | Your email address and the contents of the message being sent, plus whether it was delivered, bounced, or reported as spam | resend.com/legal/privacy-policy |
| Data Type | Retention Period |
|---|---|
| Profile (name, email) | Until you delete your account |
| Point balances (including community points) | Until you delete your account |
| Transaction history | Retained indefinitely in anonymized form after account deletion (see Section 6) |
| Engagement score snapshots | Until you delete your account |
| Consent records (including IP) | Until you delete your account |
| Earn and redemption codes | Automatically deleted upon use or expiration (minutes) |
| Receipt photos | Never stored. Held in memory only while being read (seconds), then discarded — see Section 2.10 |
| Receipt fingerprints (business, printed date and time, total) | Kept while your account exists, so the same receipt cannot be claimed twice |
| Error logs | 90 days, then automatically purged — including any that reference a since-deleted account (see Section 6) |
| Push subscriptions | Until you turn deal alerts off, revoke notification permission, delete your account, or the push service reports the subscription is dead |
| Email suppressions (an address that bounced, or whose owner unsubscribed or reported a message as spam) | Kept so that nothing further is sent to that address. A bounce is dropped after about 180 days, in case the address is repaired. An unsubscribe or a spam report is kept indefinitely, including after the account is deleted: the record is what stops us mailing that address again, so deleting it would undo the very request it exists to honour. It holds the address and the reason only |
| Deal delivery records and frequency counters | About 30 days after the deal expires; deleted immediately if you delete your account |
| Your invite code | Until you delete your account |
| Referral records (which account invited which) | Until either account is deleted, whichever comes first |
| Bonus-point records (what we credited and why) | Retained indefinitely with your identity severed after account deletion (see Section 6) |
You may delete your WeRewards account at any time through the Account tab → Delete my account. When you delete your account:
One exception. If the app recorded a diagnostic error log for your account before you deleted it (see Section 2.5), that log keeps your user identifier until it is purged on its normal 90-day schedule. These logs contain no name, email, or transaction data — only the identifier and technical debugging fields. After 90 days, no identifier associated with your account remains anywhere in our systems.
Deletion is irreversible. Once deleted, your account and points cannot be recovered.
You can download a full copy of your WeRewards data at any time through Account tab → Download my data. The file is provided as a JSON file and includes your profile, your balances and community points balance, your full transaction history, your engagement scores, your deal-notification records, every bonus we have credited you and what it was for, your invite code, and your referral records.
Your referral records are limited to your side of each invitation, in line with Section 2.12: an invitation you sent appears as its date, status, and what you were paid, without any identifier for the person you invited.
As described in Section 6, you may delete your account at any time through the app.
If you believe your account information is inaccurate, contact us at [email protected].
Deal notifications. Participating vendors can send offers ("deals") to students who have earned points at that vendor. These can reach you two ways, and they always appear in the app's Deals list whether or not anything was sent to you:
Nearby spot alerts. Separately from deals, the app can notify you when you are next to a spot you have never earned points at (Section 2.9). This is a notification your own device shows while the app is open; nothing is sent to you by us, and you are told about any given spot at most once, ever. It has its own switch, Nearby spots, and turning off Deal alerts does not turn it off.
You can turn any of them off at any time under Account tab → Notifications: Deal alerts controls push notifications, Deal emails controls email, Nearby spots controls nearby alerts, and all three are independent. Turning off Deal alerts removes the push subscriptions stored for your account. Every deal email also carries an unsubscribe link, and your email or webmail app may show its own one-click "Unsubscribe" button; either one turns Deal emails off for your account. Whatever you turn off, deals continue to appear in the app's Deals list, which you can simply not open.
Other email. We do send you email about your account when something happens that you need to know about, for example a password reset code you asked for. These are not marketing, and turning off Deal emails does not stop them.
Vendors do not receive your identity for this purpose. A vendor composes the message and chooses a category of recipients (for example, "my most frequent customers over the last 90 days"). WeRewards selects the matching accounts and delivers the message. The vendor is shown only aggregate counts (how many accounts matched, how many were sent to, how many opened the message). Vendors are not given your name, email address, or any identifier as part of this feature.
Frequency limits. We cap how many of these messages any one account can receive: at most two per day and five per week, never less than four hours apart, and none between 10:00 PM and 9:00 AM Eastern Time. These are limits on all of the above taken together, not per channel and not per feature — an email counts against them exactly as a push notification does, and so does a nearby spot alert. Two per day is the total number of times WeRewards will interrupt you, whatever the reason. Where several vendors would reach you at once, we combine them into a single message. These limits are enforced by us, not by vendors.
We implement reasonable technical and organizational measures to protect your data, including encrypted data transmission (HTTPS), server-side authentication token validation, and database access controls. No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Earn codes and redemption codes are short-lived and single-use, which limits the impact of code interception.
In the event of a data breach that affects your personal information (as defined under Pennsylvania's Breach of Personal Information Notification Act, 73 P.S. §§ 2301–2329), we will notify you without unreasonable delay and in accordance with applicable law. If a breach affects 500 or more Pennsylvania residents, we will also notify the Pennsylvania Attorney General's Office as required.
WeRewards is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us at [email protected] and we will delete it promptly.
WeRewards is not affiliated with, sponsored by, or endorsed by The Pennsylvania State University. Use of a Penn State email address as an eligibility criterion does not create any relationship between WeRewards and Penn State. Penn State does not receive your WeRewards data and has no involvement in the operation of this platform.
This applies equally to any promotion limited to accounts at a Penn State email domain (Section 2.11). Such a promotion is offered by WeRewards alone. We compare the address already attached to your account against a list of domains and nothing more: we do not contact the university, we do not verify that you are enrolled, and we do not collect or infer your student status, ID number, or academic records. A university address that has been kept after graduation qualifies exactly as any other does, because we cannot and do not distinguish them.
This section applies to businesses applying to join WeRewards, not to students. If you are a student, Sections 1–11 cover you and this section does not.
When a business submits the WeRewards vendor application form, we collect: the business name, a contact person's name, a contact phone number, a contact email address, a password chosen for the future vendor terminal login, and optionally a street address, a business logo image, and a free-text message.
Passwords are stored only as a bcrypt hash — we never store or have access to the password itself.
Application information is used solely to evaluate the application, contact the applicant, and — if the application is approved — create and operate the vendor's terminal account. We do not sell vendor contact information or use it for marketing unrelated to WeRewards.
If a business address is provided, we send that address to Nominatim, a geocoding service run by the OpenStreetMap Foundation, to convert it into map coordinates for display in the student app. Only the business address is sent.
Applications are retained while under review and, if approved, for as long as the vendor account is active. Declined and withdrawn applications are retained only as long as needed for our records. A vendor's own obligations and data rights are governed by the vendor agreement signed with WeRewards.
We may update this Privacy Policy from time to time. The current version is always available in the app and at /legal/student-privacy-policy.html, and the "Last Updated" date at the top reflects the latest revision.
For material changes we will prompt you to review and accept the revised Policy the next time you open the app, and record that acceptance as described in Section 2.7. For minor changes, your continued use after the revision is posted constitutes acceptance.
For questions, concerns, or requests regarding this Privacy Policy or your data, contact:
Krish Chavan
WeRewards
Email: [email protected]