UTIL APPS ("we," "us," or "our") operates the Util Points mobile application and website (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your information when you use our Service. By using Util Points you agree to the practices described here.
1. Information We Collect
1.1 Account Information
When you sign in with Google or Apple, the respective identity provider shares with us:
- Your display name and email address
- Your profile photo (if permitted by your provider settings)
- A unique identifier from that provider, used to recognize your account
We do not see or store your social-account password.
1.2 Business Owner Information
If you register a business on Util Points, we additionally collect:
- Business name, description, category, and contact information
- Business address and geographic coordinates (latitude / longitude) for map-based discovery
- Business logo and banner images
- Branch (office) locations and operating details
1.3 Loyalty Program Data
As part of providing the core service, we record:
- Check-in history — timestamp, business visited, and purchase amount (if entered by staff)
- Stamps earned, points accumulated, and rewards issued or redeemed
- QR codes linked to your account for check-in scanning
- Transaction references entered by business staff at the time of check-in
1.4 Device and Usage Data
- Push notification token — a device identifier provided by Firebase Cloud Messaging (FCM) so we can send you reward and promotional alerts. You can revoke this at any time in your device settings.
- Analytics events — usage patterns collected via Firebase Analytics, associated with a user identifier, to help us understand feature adoption and improve the app.
- Advertising identifier — on iOS, the IDFA (Identifier for Advertisers); on Android, the Advertising ID; along with device identifiers (IDFV). These are collected only with your consent — on iOS via the App Tracking Transparency prompt. They are used to measure and attribute the effectiveness of our advertising campaigns (see Section 3.5).
- Conversion and purchase events — key funnel events (sign-up, business creation, checkout, and subscription) that may be shared with advertising platforms to measure and optimize our campaigns (see Section 3.2).
- Crash reports — stack traces and device state captured by Firebase Crashlytics when the app crashes, used solely for debugging.
- IP address and general region — logged automatically by our servers for security and fraud prevention.
1.5 Images You Upload
Profile photos and business images you upload are stored in Microsoft Azure Blob Storage in a private container accessible only through signed URLs generated by our API.
1.6 Referral Data
If you use or share a referral code, we record the referral relationship to attribute rewards to the referring user once the referred user completes qualifying check-ins.
2. How We Use Your Information and Legal Bases for Processing
In accordance with the EU General Data Protection Regulation (EU GDPR 2016/679), we process your personal data only when we have a valid legal basis:
- Performance of a contract (Art. 6.1.b GDPR): to deliver the loyalty program, record check-ins, issue stamps and points, enable reward redemptions, and manage your user account.
- Explicit consent (Art. 6.1.a GDPR): to send promotional push notifications, collect location data for business discovery on the map, place non-essential analytics and advertising cookies, and process advertising tracking identifiers (ATT). You may revoke this consent at any time.
- Legitimate interests (Art. 6.1.f GDPR): to ensure platform security, detect and prevent fraud in QR code redemptions, and maintain technical service stability through crash reporting.
- Compliance with legal obligations (Art. 6.1.c GDPR): to comply with applicable statutory, tax, or regulatory obligations and respond to lawful authority requests.
We do not sell your personal information and we do not show third-party ads inside the app. We do share a limited set of identifiers and events with advertising platforms (Meta, TikTok, Google) and with RevenueCat to measure and optimize our own acquisition campaigns — always subject to your tracking consent on our cookie banner or on iOS (App Tracking Transparency).
3. Information We Share
3.1 With Business Owners
When you check in at a business, the business owner and authorized staff can see your display name and your check-in history at their business only. They cannot see your activity at other businesses.
3.2 Service Providers (Sub-processors)
| Provider | Data shared | Purpose |
|---|---|---|
| Google / Firebase | Account credentials, device tokens, analytics events, crash traces | Authentication, push notifications, analytics, crash reporting |
| Microsoft Azure | Images you upload (profile photo, business logo/banner) | Cloud image storage |
| Apple | Email and name (for Sign in with Apple accounts) | Authentication |
| Google Maps Platform | Business address for geocoding; device location for map display | Business discovery map |
| Meta Platforms (Facebook / Instagram) | Advertising identifier (IDFA / Advertising ID), user identifier, hashed email, conversion and purchase events | Advertising campaign measurement and optimization |
| TikTok | Advertising identifier (IDFA / Advertising ID), user identifier, hashed email, conversion and purchase events | Advertising campaign measurement and optimization |
| RevenueCat | User identifier, device identifiers, purchase and subscription history | Subscription management and revenue attribution to campaigns |
3.3 Third-Party Privacy Policies
- Google / Firebase: policies.google.com/privacy
- Microsoft Azure: privacy.microsoft.com
- Apple: apple.com/legal/privacy
- Google Maps Platform: cloud.google.com/maps-platform/terms
- Meta: facebook.com/privacy/policy
- TikTok: tiktok.com/legal/privacy-policy
- RevenueCat: revenuecat.com/privacy
3.4 Legal Disclosure
We may disclose personal information if required by law, subpoena, court order, or other governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
3.5 Advertising and Campaign Attribution
We promote Util Points through campaigns on Meta (Facebook and Instagram), TikTok, Google, and the app stores (App Store and Google Play). To understand which campaigns work, we share a limited set of data with those platforms: the device advertising identifier (IDFA on iOS / Advertising ID on Android), a user identifier, your email in hashed form (not in clear text), and conversion events (sign-up, business creation, checkout, and subscription).
- iOS: the advertising identifier (IDFA) is used only if you allow it in the App Tracking Transparency prompt. If you decline, measurement is performed in aggregate via Apple's SKAdNetwork, without identifying you. Apple Search Ads attribution uses Apple's AdServices framework.
- Android: the Advertising ID is used according to your device's ad settings, which you can reset or disable at any time.
Purchases and subscriptions are reported to these platforms through RevenueCat (server-to-server) to measure advertising return on investment. We do not share your information so that third parties can show you ads inside Util Points (there are no ads in the app); the sole purpose is to measure and optimize our own campaigns. You can disable tracking as described in Section 7.6.
4. Children's Privacy
Util Points is intended for users 13 years of age and older. Users between 13 and 17 must obtain parental or guardian consent before creating an account. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child under 13 has provided us personal information without your consent, please contact us at info@utilpoints.app and we will delete it promptly.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service.
- Account deletion — your personal profile is permanently removed within 30 days of requesting deletion.
- Check-in records — may be kept in anonymized, aggregated form for up to 12 months for analytics and fraud-prevention purposes.
- Business data — retained for 90 days after account deletion to support dispute resolution.
- Backup copies — may persist for up to 30 additional days in encrypted backups before being purged.
6. Security
We implement industry-standard safeguards, including:
- HTTPS / TLS encryption for all data in transit
- Firebase Authentication with signed JWTs validated server-side on every request
- Role-based access controls — business staff can only access data for their own business
- Encrypted storage for secrets and API credentials (never committed to source control)
- Soft-delete design — records are deactivated rather than immediately destroyed, enabling recovery and audit trails
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but will notify you of a breach as required by applicable law.
7. Your Rights and Choices
7.1 Access and Correction
You can view and update your name and profile photo directly in the app at any time.
7.2 Account Deletion
You can delete your account from Settings → Delete account inside the app. Upon deletion, personal data is removed as described in Section 5.
For detailed step-by-step instructions and additional options, please consult our dedicated Data Deletion Instructions page.
7.3 Push Notifications
You can opt out of push notifications at any time in your device's notification settings (iOS: Settings → Notifications → Util Points; Android: Settings → Apps → Util Points → Notifications).
7.4 Location
Location access is optional and requested only for the business-discovery map feature. You can deny or revoke this permission in your device settings without affecting the rest of the app.
7.5 Data Portability
To request a copy of the personal data we hold about you, email info@utilpoints.app with the subject line "Data Export Request."
7.6 Ad Tracking (App Tracking Transparency)
On iOS, the app asks for permission via App Tracking Transparency before using your advertising identifier. You can change your choice at any time in Settings → Privacy & Security → Tracking. On Android, you can reset or delete your Advertising ID in Settings → Privacy → Ads. If you disable tracking, you can keep using Util Points normally; only the accuracy of advertising measurement is reduced.
7.7 Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
If you consider that our processing of your personal data infringes applicable data protection law or you are dissatisfied with our response to your privacy rights, you have the right to lodge a complaint with a competent Data Protection Supervisory Authority. If you reside in Spain, you may lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es. If you reside in another European Union member state, you may contact your national supervisory authority.
7.8 Privacy Rights for California Residents (CCPA / CPRA & CalOPPA)
In accordance with the California Consumer Privacy Act (CCPA, as amended by the CPRA), CalOPPA, and applicable US state privacy laws (Virginia VCDPA, Colorado CPA, Texas TDPSA):
- Right to Know & Access: you have the right to request the categories and specific pieces of personal information we have collected, used, disclosed, or shared about you over the past 12 months.
- Right to Delete: you have the right to request the deletion of your personal information, subject to statutory exceptions.
- Right to Correct: you have the right to request the correction of inaccurate personal information in your account.
- Right to Opt-Out of Sale & Sharing: we do not sell your personal information for monetary payment. However, sharing online identifiers with advertising platforms (such as Meta Pixel or Google Ads) for cross-context behavioral advertising is classified as "sharing" under CCPA. You may exercise your right to opt-out at any time using the link in the footer.
- Global Privacy Control (GPC) Signal Recognition: our website automatically detects and honors the browser-based
Global Privacy Control (GPC)signal. If your browser transmits an active GPC signal, we treat your session as an automatic Opt-Out of advertising sharing. - CalOPPA Do Not Track (DNT) Disclosure: because there is no unified industry standard for legacy DNT header signals, we recognize and respond to the GPC technical specification.
- California Shine the Light Law: California residents may request once per year a list of personal information categories shared with third parties for direct marketing purposes (if applicable) by emailing us at info@utilpoints.app.
- Non-Discrimination: we will not discriminate against you in price, quality, or service availability for exercising any of your privacy rights under California law.
8. Cookies and Similar Technologies
Our mobile app does not use cookies. Our website uses strictly necessary cookies for functionality and language preference. Non-essential analytics and advertising cookies (such as Meta Pixel or Google Ads tags) are only set after obtaining your explicit consent via our Cookie Banner (CMP). You can review or adjust your cookie preferences at any time using the link in the footer.
9. International Data Transfers and Safeguards (Chapter V GDPR)
Util Points is operated from the United States and uses global cloud infrastructure providers. To ensure an adequate level of data protection when personal data is transferred outside the European Economic Area (EEA):
- EU-US Data Privacy Framework (DPF): Our primary U.S.-based sub-processors (Google LLC, Microsoft Corporation, Meta Platforms Inc., RevenueCat Inc.) participate in and are certified under the EU-U.S. Data Privacy Framework approved by the European Commission.
- Standard Contractual Clauses (SCCs): Where required, we execute the European Commission's Standard Contractual Clauses (Implementing Decision EU 2021/914) incorporated into our Data Processing Agreements (DPAs) with each service provider.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will:
- Display an in-app notice at the next login
- Update the "Last updated" date at the top of this page
Your continued use of the Service after the effective date constitutes your acceptance of the updated policy. If you do not agree, please stop using the Service and delete your account.
11. Contact Us & EU Representative
For privacy-related questions, requests to exercise GDPR rights, or complaints, please contact us:
UTIL APPS
Global Privacy Email: info@utilpoints.app
EU Representative Contact (Art. 27 GDPR): info@utilpoints.app (Subject: EU Privacy Officer)
Full Corporate Legal Notice (Impressum): www.utilpoints.app/en/legal-notice