UTIL APPS ("we," "us," or "our") operates the UtilPoints mobile application and website (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our Service. By using UtilPoints you agree to the practices described here.
1. Information We Collect
1.1 Account Information
When you sign in with Google or Apple, the respective identity provider shares with us:
- Your display name and email address
- Your profile photo (if permitted by your provider settings)
- A unique identifier from that provider, used to recognize your account
We do not see or store your social-account password.
1.2 Business Owner Information
If you register a business on UtilPoints, we additionally collect:
- Business name, description, category, and contact information
- Business address and geographic coordinates (latitude / longitude) for map-based discovery
- Business logo and banner images
- Branch (office) locations and operating details
1.3 Loyalty Program Data
As part of providing the core service, we record:
- Check-in history — timestamp, business visited, and purchase amount (if entered by staff)
- Stamps earned, points accumulated, and rewards issued or redeemed
- QR codes linked to your account for check-in scanning
- Transaction references entered by business staff at the time of check-in
1.4 Device and Usage Data
- Push notification token — a device identifier provided by Firebase Cloud Messaging (FCM) so we can send you reward and promotional alerts. You can revoke this at any time in your device settings.
- Analytics events — aggregated, anonymized usage patterns collected via Firebase Analytics to help us understand feature adoption and improve the app.
- Crash reports — stack traces and device state captured by Firebase Crashlytics when the app crashes, used solely for debugging.
- IP address and general region — logged automatically by our servers for security and fraud prevention.
1.5 Images You Upload
Profile photos and business images you upload are stored in Microsoft Azure Blob Storage in a private container accessible only through signed URLs generated by our API.
1.6 Referral Data
If you use or share a referral code, we record the referral relationship to attribute rewards to the referring user once the referred user completes qualifying check-ins.
2. How We Use Your Information
- Deliver the loyalty program — record check-ins, issue stamps and points, track reward milestones, and enable redemption by authorized business staff.
- Send notifications — alert you about earned rewards, promotions from businesses you follow, and important account updates. You may opt out at any time in your device notification settings.
- Business discovery — display nearby businesses and their loyalty campaigns on the explore map using your device location (only if you grant location permission).
- Business analytics — provide business owners with aggregated statistics about visits, retention, and reward redemption. Individual customer data is never shared with third parties for marketing purposes.
- Customer support — respond to inquiries, resolve disputes, and troubleshoot issues.
- Fraud and abuse prevention — detect and block unauthorized use of check-in codes or reward redemptions.
- Legal compliance — meet applicable legal and regulatory obligations.
We do not sell your personal information to third parties, and we do not use it for targeted advertising.
3. Information We Share
3.1 With Business Owners
When you check in at a business, the business owner and authorized staff can see your display name and your check-in history at their business only. They cannot see your activity at other businesses.
3.2 Service Providers (Sub-processors)
| Provider | Data shared | Purpose |
|---|---|---|
| Google / Firebase | Account credentials, device tokens, analytics events, crash traces | Authentication, push notifications, analytics, crash reporting |
| Microsoft Azure | Images you upload (profile photo, business logo/banner) | Cloud image storage |
| Apple | Email and name (for Sign in with Apple accounts) | Authentication |
| Google Maps Platform | Business address for geocoding; device location for map display | Business discovery map |
3.3 Third-Party Privacy Policies
- Google / Firebase: policies.google.com/privacy
- Microsoft Azure: privacy.microsoft.com
- Apple: apple.com/legal/privacy
- Google Maps Platform: cloud.google.com/maps-platform/terms
3.4 Legal Disclosure
We may disclose personal information if required by law, subpoena, court order, or other governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
4. Children's Privacy
UtilPoints is intended for users 13 years of age and older. Users between 13 and 17 must obtain parental or guardian consent before creating an account. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child under 13 has provided us personal information without your consent, please contact us at info@utilpoints.app and we will delete it promptly.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service.
- Account deletion — your personal profile is permanently removed within 30 days of requesting deletion.
- Check-in records — may be kept in anonymized, aggregated form for up to 12 months for analytics and fraud-prevention purposes.
- Business data — retained for 90 days after account deletion to support dispute resolution.
- Backup copies — may persist for up to 30 additional days in encrypted backups before being purged.
6. Security
We implement industry-standard safeguards, including:
- HTTPS / TLS encryption for all data in transit
- Firebase Authentication with signed JWTs validated server-side on every request
- Role-based access controls — business staff can only access data for their own business
- Encrypted storage for secrets and API credentials (never committed to source control)
- Soft-delete design — records are deactivated rather than immediately destroyed, enabling recovery and audit trails
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify you of a breach as required by applicable law.
7. Your Rights and Choices
7.1 Access and Correction
You can view and update your name and profile photo directly in the app at any time.
7.2 Account Deletion
You can delete your account from Settings → Delete account inside the app. Upon deletion, personal data is removed as described in Section 5.
7.3 Push Notifications
You can opt out of push notifications at any time in your device's notification settings (iOS: Settings → Notifications → UtilPoints; Android: Settings → Apps → UtilPoints → Notifications).
7.4 Location
Location access is optional and requested only for the business-discovery map feature. You can deny or revoke this permission in your device settings without affecting the rest of the app.
7.5 Data Portability
To request a copy of the personal data we hold about you, email info@utilpoints.app with the subject line "Data Export Request."
8. Cookies and Similar Technologies
Our mobile app does not use cookies. Our website uses only essential session cookies for language-preference storage. We do not use advertising, tracking, or analytics cookies on the website.
9. International Data Transfers
UtilPoints is operated from the United States. If you are located outside the U.S., your information may be transferred to and processed in the United States. By using the Service you consent to this transfer. We use service providers that participate in recognized data transfer frameworks to ensure appropriate safeguards are in place.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Display an in-app notice at the next login
- Update the "Last updated" date at the top of this page
Your continued use of the Service after the effective date constitutes your acceptance of the updated policy. If you do not agree, please stop using the Service and delete your account.
11. Contact Us
For privacy-related questions, requests, or complaints please contact us:
UTIL APPS Email: info@utilpoints.appWebsite: utilpoints.app