Privacy Policy
How ScanReward collects, uses, protects and stores your information.
This page is maintained by ScanReward by GoGee.ai as app-owned editable content. It describes our current practices and the controls available to users. This policy is not a legal certification or legal advice; it is provided to help users understand how their data is handled.
1. What this policy covers
This Privacy Policy applies to the ScanReward platform and services operated by GoGee.ai. It explains what information we collect when businesses use our loyalty, voucher and engagement tools, and when end-customers register, redeem vouchers or interact with campaigns through ScanReward.
2. Information we collect
- Account and business information — business name, contact details, branch information and user login credentials for authorised staff.
- Customer information — first name, last name, email address, mobile phone number, date of birth (where provided) and marketing consent preferences collected during registration or campaign sign-up.
- Usage and transaction data — voucher redemptions, loyalty points earned or redeemed, campaign interactions, referral activity and customer support requests.
- Communications metadata — message delivery status, WhatsApp/SMS thread metadata and support communications necessary to operate the service.
3. How we use information
- Provide, operate and maintain the ScanReward platform;
- Deliver vouchers, loyalty rewards and campaign messages to customers;
- Process redemptions, referrals and customer transactions;
- Enable businesses to analyse campaign performance and customer engagement;
- Send service-related notifications and, where consent is given, marketing communications;
- Provide customer support and improve the platform.
4. Legal basis and consent
We process personal information where we have a lawful basis to do so, such as to perform our contract with the business, to comply with legal obligations, or where the individual has provided consent (for example, by opting in to marketing during registration). Customers can withdraw marketing consent at any time by following the unsubscribe instructions in messages or by contacting us.
5. Sharing and subprocessors
We do not sell personal information. We share data only with service providers who help us operate the platform, and with the business that invited the customer to use ScanReward. Current service providers include:
- Supabase — cloud hosting, database and authentication infrastructure.
- Twilio — WhatsApp and SMS message delivery. For WhatsApp, Twilio sends messages through the business's own verified WhatsApp Business number, which is linked to the business's Meta account.
- SendGrid — transactional and support email delivery.
- PayFast — payment processing for subscriptions and top-ups.
- Meta Platforms (Facebook / Instagram) — where a business connects its own Meta Ad Account in the Audience Builder, ScanReward transmits customer contact identifiers to Meta's Marketing API (Custom Audiences) so the business can retarget or exclude its own customers in its own advertising campaigns. See section 6 for exactly what is sent and how it is protected.
- Google Ads — where a business connects its own Google Ads account, ScanReward can upload customer contact identifiers to Google Customer Match for the same purpose.
The specific subprocessors in use depend on the features a business has enabled in its account settings. Advertising integrations are opt-in per business and per customer.
6. Advertising audience sync (Meta & Google)
The Audience Builder lets a business push a list of its own customers to advertising platforms it controls, so that it can (a) show ads to those customers, (b) build lookalike audiences from them, or (c) exclude them from campaigns. This feature is only active when the business has connected its own Meta Ad Account or Google Ads account.
What we send to Meta / Google. For each customer included in the sync, we transmit only the following fields, and only for customers who have given marketing consent within ScanReward:
- Email address
- Mobile phone number (E.164 format)
- First name and last name (where available, to improve match rate)
Hashing. Before leaving ScanReward, every identifier is normalised (lower-cased, trimmed, phone numbers reduced to digits) and irreversibly hashed with SHA-256 in line with Meta's Customer List Custom Audiences requirements and Google's Customer Match requirements. We do not send raw email addresses or phone numbers to Meta or Google.
Purpose limitation. The hashed identifiers are used by Meta or Google only to match against their existing users so the connected business can target or exclude its own customers. ScanReward does not use these transfers to build advertising profiles across unrelated businesses.
Legal basis. We rely on the customer's marketing consent captured at registration (or later opt-in), together with the connected business's legitimate interest in marketing to its own customer base. Customers who have not opted in to marketing are excluded from advertising audience syncs.
Meta & Google as independent controllers. Once identifiers reach Meta or Google, those platforms process them under their own terms as independent or joint controllers, including their Custom Audiences / Customer Match terms. Their privacy policies are available at facebook.com/policy.php and policies.google.com/privacy.
Your rights. A customer can withdraw marketing consent at any time via the unsubscribe link in any message or by contacting the business, which will remove them from future audience syncs. Customers can also request removal from an existing advertising audience by contacting us at the email in section 13; on such a request we will remove their hashed identifiers from the connected Meta or Google audience(s) operated on behalf of the business, and can also opt out directly through Meta at facebook.com/ads/preferences or Google at myadcenter.google.com.
Retention. ScanReward retains the source customer record according to section 7. The resulting audience stored inside Meta or Google is retained under those platforms' own retention rules and can be deleted at any time by the connected business from its Ads Manager account.
7. Data retention
We retain account and transaction data for as long as the business account is active or as needed to provide the service, comply with legal obligations and resolve disputes. Customer data is retained according to the retention settings chosen by the business or required by applicable law. When an account is closed, we delete or anonymise personal information unless we are required to keep it for legal or audit purposes.
8. Your choices and rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you;
- Request correction or deletion of your personal information;
- Object to or restrict certain processing;
- Withdraw consent for marketing communications;
- Export your data in a portable format.
To exercise these rights, please contact us using the details below. Customers may also contact the business that invited them to ScanReward directly.
9. Security
We use industry-standard technical and organisational measures to protect data, including encryption in transit, access controls, row-level security policies and regular monitoring. No system is completely secure, and we encourage users to protect their account credentials and report suspicious activity.
10. International transfers
Our hosting and subprocessors may process data in regions outside your own. Where this occurs, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms to protect your information.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post any changes on this page with an updated effective date. Continued use of the platform after changes are posted constitutes acceptance of the revised policy.
12. Contact us
If you have questions about this Privacy Policy or how your data is handled, please contact us:
Effective date: 7 October 2026.
