1. Introduction
PointClub ("we", "us", "our") is operated by Point Club (Private) Limited, a company incorporated in Pakistan (SECP Incorporation No. 0331020, NTN I763370), with its registered office at 4 Mavani Chambers, off I.I. Chundrigar Road, Karachi, Pakistan.
We operate the PointClub and PointClub Merchant mobile applications (the "Apps") and associated backend services. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our loyalty points platform.
PointClub primarily serves businesses and consumers within Pakistan. By using our Apps, you agree to the collection and use of information as described in this policy.
2. Information We Collect
2.1 Customer Information
When you create a PointClub customer account, we collect:
- Full name -to personalise your experience
- Email address -for account authentication, verification, and password recovery
- Phone number -for account verification and WhatsApp notifications (Pakistani mobile numbers in +92 format)
- Password -securely hashed and stored; we never store or view your plaintext password
- Date of birth -optional; provided only if you choose to receive birthday rewards and promotions
2.2 Merchant Information
When you register a business on PointClub Merchant, we collect:
- Business name and category -displayed publicly to customers
- Owner name -for account management
- Business email and phone number -for account authentication and communication
- Business logo -uploaded images stored securely for branding loyalty cards
- Brand colours -custom colour preferences for loyalty card display
- Points configuration -earning rates and redemption values
2.3 Staff Information
Merchant owners may add staff members. We collect:
- Name, phone number, and email -for account creation and OTP verification
- Role and permissions -to control access within the merchant platform
2.4 Transaction Data
When loyalty points are earned or redeemed, we record:
- Transaction amount (in PKR), points earned or redeemed, and resulting balance
- Order or receipt ID provided by the merchant
- Timestamp and associated merchant and customer identifiers
2.5 Device and Usage Data
- IP address and user agent -recorded in audit logs for security monitoring
- Location data -approximate GPS coordinates (medium accuracy) used to find nearby merchants; only collected when you use the "Nearby" feature and grant location permission
- Camera access -used solely for scanning QR codes (merchant app scans customer QR; customer app scans at merchant locations)
- Photo library access -used by merchants to upload business logos
- Local storage -authentication tokens, theme preferences, and cached data stored on your device
2.6 Referral and Invite Codes
PointClub merchants and their staff each receive a personal referral code they can share to invite others to join PointClub. When you sign up using a referral or invite code, we record:
- The referral or invite code you entered at sign-up
- The merchant or staff member to whom that code belongs, so the sign-up can be attributed to them
This links your new account to the merchant or staff member who referred you. We use it only to count how many sign-ups each referral code has produced. The referrer can see the number of sign-ups attributed to their code — not your identity or account details. See Section 6.1 for how this is shared.
2.7 Optional Date of Birth
You may choose to provide your date of birth in the customer app so PointClub can offer birthday rewards and promotions. Providing your date of birth is optional; you can omit it and still use PointClub.
We use your date of birth solely to determine birthday reward and promotion eligibility. The App derives and stores a server-side birthday key for eligibility matching; merchants do not receive your raw date of birth. Birthday eligibility is used to grant promotions and may be reflected to a redeeming merchant only as needed to honor a birthday reward.
Your date of birth is set once in the app. To correct or remove it, contact support at support@pointclub.pk; deleting your account also removes it. Date-of-birth data is retained according to the existing retention policy in Section 5.
2.8 Support View-As Sessions
When needed to investigate an approved support request, authorised support staff may start a time-limited, read-only "view-as" session for a customer, merchant owner, or merchant staff account. We record the support user, target account, reason code, ticket reference, timestamps, IP address, user agent, session status, and mandatory access audit events. Support view-as sessions do not let support staff modify your account, points, transactions, or merchant data.
2.9 Social Sign-In (Google & Apple)
You may choose to create or access your PointClub customer account using "Sign in with Google" or "Sign in with Apple" instead of an email-and-password login. Using social sign-in is optional — you can always register and log in with an email and password instead.
When you sign in this way, the provider (Google or Apple) sends us a signed sign-in token confirming your identity. From that token we collect and store:
- Email address -used to create or locate your PointClub account. With "Sign in with Apple" you may choose Apple's Hide My Email option, in which case we receive a private Apple relay address instead of your real email.
- A provider account identifier -a stable identifier contained in the token that we store to link your Google or Apple sign-in to your PointClub account on future logins, together with technical token metadata such as the token's issuer and intended audience.
We do not receive your name from Google or Apple; your PointClub display name is the name you enter in the App, or a generic placeholder if you do not provide one. We use this information solely to authenticate you and to create or link your PointClub account, and we never receive or store your Google or Apple password. Once you have signed in with Google or Apple, your PointClub account is linked to that provider; for security, password-based login and in-app email changes are then disabled for that account and you continue to sign in with the same provider. Social sign-in is governed by the providers' own privacy policies (see Section 6.2).
2.10 Information We Do NOT Collect
- We do not collect payment card or bank account information
- We do not collect contacts, call logs, or browsing history
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Account creation and authentication | Name, email, phone, password |
| Social sign-in (Sign in with Google / Apple) | Provider sign-in token, email (or Apple relay email), provider account identifier, token issuer/audience |
| Loyalty points earning and redemption | Transaction data, enrollment data |
| QR code generation and validation | Enrollment ID, cryptographic nonces |
| Merchant branding and loyalty card display | Logo, brand colours, business name |
| Staff management and access control | Staff name, phone, role, permissions |
| WhatsApp and email notifications and OTP verification | Phone number, email address |
| Security monitoring and fraud prevention | IP address, user agent, audit logs |
| Business analytics and reporting | Aggregated transaction and points data |
| Personalised offers and promotions | Transaction history, enrollment data, points balance |
| Birthday rewards and promotion eligibility | Optional date of birth, server-derived birthday key, birthday eligibility status |
| Referral attribution and reward reconciliation | Referral/invite code, referrer identity, sign-up count |
| Support troubleshooting and read-only view-as assistance | Support query context, reason code, ticket reference, account identifiers, IP address, user agent, session and audit records |
| Improving pricing and service features | Aggregated usage patterns and transaction trends |
| In-app personalised offers and promotional content | Customer preferences, merchant enrollment data, transaction patterns |
4. Data Storage and Security
4.1 Where We Store Data
All data is stored on Amazon Web Services (AWS) infrastructure in the Asia Pacific (Singapore) -ap-southeast-1 region. This includes:
- AWS Cognito -secure user authentication with hashed passwords
- AWS DynamoDB -encrypted database for user profiles, transactions, and enrollments
- AWS S3 -encrypted storage for merchant logos and audit log archives
4.2 Security Measures
- All data transmitted over HTTPS/TLS encryption
- Server-side AES-256 encryption for all stored data
- Passwords hashed using AWS-managed key derivation (never stored in plaintext)
- Single-use cryptographic nonces for QR code transactions (prevents replay attacks)
- HMAC signatures for QR code integrity verification
- Role-based access control (RBAC) for merchant staff
- Read-only, time-limited support view-as sessions with mandatory audit logging
- Automatic token expiry and refresh mechanisms
- Comprehensive audit logging of all security-relevant events
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Customer and merchant accounts | Until account deletion is requested |
| Optional date of birth | Until removed by the customer or account deletion is requested |
| Transaction records | Retained indefinitely for accounting and dispute resolution |
| Enrollment records | Until cancelled by the customer |
| Support view-as session and access audit records | Retained with support and audit records for compliance, security, and dispute resolution |
| Audit logs (active) | 30 days in primary database |
| Audit logs (archive) | Archived to cold storage indefinitely for compliance |
| OTP codes | 5–10 minutes (automatically deleted) |
| QR code nonces | 5 minutes (automatically deleted) |
| Merchant logos | Until replaced or account deleted |
| Staff accounts | Until deleted by the merchant owner |
5.1 Account Deletion
Customers can delete their PointClub account at any time in the app by going to Profile → Settings → Delete Account. If you cannot access the app, you may also request deletion by emailing support@pointclub.pk from the email address registered on your account.
Merchant staff and owners can delete their personal PointClub Merchant account at any time in the app by going to Profile → Account → Delete My Account. Profile deletion is immediate and irreversible. If you are the sole owner of a business, deleting your account also submits a business closure request that our support team will review separately; your personal profile is still removed immediately.
Business closure can be requested separately by business owners via Profile → Account → Request Business Closure. Support reviews these requests and coordinates customer notification, billing settlement, and staff removal. Business closure does not affect day-to-day operations until support approves it.
We publish step-by-step web instructions for both account types at /delete-account. That page explains the full process, the data that is deleted, and the records we must retain.
When an account is deleted, we permanently remove personal profile data (name, email, phone number) and associated records such as loyalty enrollments, device tokens, wallet passes, punch card progress, promotion redemption history, and audience memberships.
Records of business actions you authorised while operating a business — transactions you created, approvals you issued, and audit events you generated — are retained on behalf of that business and continue to show your name, email, and role as captured at the moment of each action. This retention is required to support the business's audit, billing, fraud-prevention, and regulatory obligations, and is permitted under applicable data-protection law.
6. Data Sharing
6.1 With Merchants
When you enrol in a merchant's loyalty programme, that merchant can see your unique customer identifier (UUID), points balance, and transaction history with them. Your name, email address, and phone number are never shared with merchants. Merchants cannot see your activity with other merchants.
If you redeem a birthday reward, the redeeming merchant may see that the birthday reward applies so they can honor the promotion. Merchants do not receive your raw date of birth.
If you sign up using a merchant's or staff member's referral code, that merchant or staff member can see the total number of sign-ups their code has produced — they cannot see which individual customers signed up, or any of your personal details, through the referral feature. Our support team can view and reconcile these referral counts per merchant.
6.2 With Service Providers
We use the following third-party services to operate PointClub:
- Amazon Web Services (AWS) -cloud infrastructure, authentication, database, and storage. Data is stored in the Asia Pacific (Singapore) region (ap-southeast-1).
- Resend (Resend, Inc.) -transactional email delivery. Resend may process your email address and message metadata. Resend's data handling is governed by their privacy policy at https://resend.com/legal/privacy-policy
- Google Firebase -We use Firebase for:
- Push notifications -device tokens linked to your account for delivering transaction and account notifications via Firebase Cloud Messaging (FCM)
- Crash reporting -error data, stack traces, device information, and your account identifier (internal UUID, not your name or email) via Firebase Crashlytics, to diagnose and fix app issues
- Analytics -screen views, feature usage events (e.g., enrollment, transactions, profile updates), and your account identifier (internal UUID) via Firebase Analytics, to understand how the app is used and improve it. We also collect your user type (customer, merchant, or support) and, if provided during signup, your gender as analytics properties.
Firebase may assign a device identifier and correlate your analytics, crash reports, and push notification data using your account identifier. Your name, email address, and phone number are not sent to Firebase. Firebase's data handling is governed by Google's Privacy Policy.
- Google Sign-In (Google LLC) -if you choose "Sign in with Google", Google authenticates you and provides us a signed sign-in token containing your email and a Google account identifier so we can create or access your PointClub account. Google's handling of your information is governed by Google's Privacy Policy.
- Sign in with Apple (Apple Inc.) -if you choose "Sign in with Apple", Apple authenticates you and provides us a signed sign-in token containing a provider identifier and either your email or, if you choose Hide My Email, an Apple private relay email, so we can create or access your PointClub account. Apple's handling of your information is governed by Apple's Privacy Policy.
- Google Analytics 4 and Meta Pixel -used across our website only (pointclub.pk), not in the mobile Apps. On every page of our website these services record the page viewed, your approximate location (derived from IP address), your device and browser type, and the link that referred you. On our app-download pages they additionally record which app store you were sent to. We use this to see whether our printed QR codes and campaigns actually lead to app downloads. These services set cookies and may use the data for their own analytics and, in Meta's case, advertising measurement and audience building. The pages involved are public and require no sign-in, so no PointClub account data, name, email address, or phone number is sent to either service. Their handling of this data is governed by Google's Privacy Policy and Meta's Privacy Policy. You can opt out with the Google Analytics Opt-out Browser Add-on, your browser's cookie controls, or any tracking-blocker extension — blocking them does not affect your ability to download or use the Apps.
We do not sell or rent your personal information to any third parties for their marketing purposes.
6.3 Legal Requirements
We may disclose your information if required by law, court order, or government authority under the laws of Pakistan, including but not limited to the Prevention of Electronic Crimes Act 2016 (PECA) and any applicable data protection regulations.
7. Your Rights
You have the right to:
- Access your personal data -view your profile and transaction history in the App
- Correct inaccurate data -update your name and phone number in the App; to correct or remove your optional date of birth or gender, contact support.
- Delete your account -use the in-app flow at Profile → Settings → Delete Account, visit /delete-account, or email support@pointclub.pk
- Cancel enrolments -unenrol from any merchant's loyalty programme at any time
- Opt out of promotional communications -via App settings or by contacting us
- Data portability -request a copy of your data by contacting us
We will respond to your request within 30 days.
8. Children's Privacy
PointClub is not intended for children under the age of 18. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us immediately at support@pointclub.pk and we will delete such information.
9. WhatsApp and Email Communications
We send messages to Pakistani mobile numbers (+92) via WhatsApp, and to your registered email address via Resend, for:
- One-time passwords (OTP) for account verification and login (via WhatsApp or email)
- Email verification links for account signup and email address changes
- Password reset codes
- Account-ready confirmation emails after successful registration
- Initial staff account password delivery (via WhatsApp)
- Staff and support user onboarding invitations (via email)
- Transactional notifications related to your account and loyalty activity
These are transactional messages essential for account security and service delivery. We do not send marketing or promotional emails or WhatsApp messages unless you have explicitly opted in.
9.1 WhatsApp Messaging
We use the WhatsApp Business Platform to deliver one-time passwords (OTPs) and transactional notifications to your registered phone number. By providing your phone number during account registration, you consent to receiving these messages via WhatsApp.
WhatsApp messages are sent through Meta's WhatsApp Business API. Meta may process your phone number and message delivery metadata in accordance with WhatsApp's Privacy Policy. We do not share any other personal information with Meta beyond what is required to deliver the message.
9.2 Opting Out
You may opt out of WhatsApp messages at any time by contacting us at support@pointclub.pk. Note that opting out of required verification messaging may prevent you from verifying your account or completing security-sensitive actions.
10. Cookies and Local Storage
Our Apps do not use browser cookies. We store the following data locally on your device using secure local storage:
- Authentication tokens (cleared on logout)
- Theme preference (light/dark/system)
- Last login identifier (for convenience)
- Cached merchant profile data (for instant loading)
- Hidden and favourite loyalty card preferences
All locally stored data is cleared when you log out of the App.
Our website is different. Every page on pointclub.pk sets analytics and advertising-measurement cookies through Google Analytics and the Meta Pixel, as described in Section 6.2. You can block or clear these through your browser settings or a tracking blocker; doing so has no effect on the PointClub Apps.
11. International Data Transfers
Your data is primarily stored in the AWS Asia Pacific (Singapore) region. While AWS may process data globally for infrastructure management, your personal data remains within the AWS ap-southeast-1 region. By using PointClub, you consent to the storage of your data in Singapore-based AWS data centres. Google Firebase services may process device data, crash reports, analytics events, and your account identifier (internal UUID) in Google's global infrastructure as described in Section 6.2.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the App or via email. The "Last Updated" date at the top of this policy indicates when it was last revised.
13. Governing Law
This Privacy Policy is governed by the laws of Pakistan, including the Prevention of Electronic Crimes Act 2016 (PECA) and any future data protection legislation enacted in Pakistan.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Email: support@pointclub.pk
- Website: www.pointclub.pk