Legal

Privacy Policy

Effective Date: July 18, 2026

1. Who We Are & Scope

Redeema, LLC ("Redeema," "we," "us," or "our") is a FinTech platform incorporated in Puerto Rico that operates a Community Operating System — enabling organizations such as sports leagues, graduating classes, schools, and faith communities to manage dues, fundraising campaigns, events, sweepstakes, memberships, and business-sponsored Kickback programs. This Privacy Policy governs all personal data collected through our mobile applications, web portals, and business-facing tools across Puerto Rico and the United States.

  • End users of the Redeema mobile application and web platform
  • Organization administrators (leagues, schools, classes, faith communities)
  • Business partners who create and fund Kickback campaigns
  • Parents and guardians who interact on behalf of minor participants

We adhere to the principle of Privacy by Design: data collection is limited strictly to what is necessary for platform functionality.

2. Information We Collect

2.1 Information You Provide Directly

  • Account registration: name, email address, phone number.
  • Organization profile: organization name, logo, administrator contact information, and EIN (for business accounts).
  • Participant data entered by authorized administrators: first name, last name, group assignment, and Parent/Guardian name and email (for minor participants).
  • Payment initiation: processed entirely by Stripe. Redeema does not store card numbers, bank account numbers, or full payment credentials for any user or organization.
  • Business payment method for Kickback: a sponsoring business saves a payment method through Stripe's secure setup process so approved kickbacks can be charged off-session. This credential is held by Stripe, not by Redeema.
  • Communications: messages submitted via support channels or contact forms.

2.2 Information Collected Automatically

  • Device identifiers and IP addresses (used for fraud prevention and audit-log integrity)
  • Session data and usage logs (pages visited, actions taken, timestamps)
  • Referral and attribution data — when a campaign is shared, a deeplink may carry a member identifier so participation can be attributed to the member who shared it. Links opened from an organization page carry no member attribution.
  • AWS CloudWatch performance and error logs
  • Google Analytics aggregate traffic data (no cross-site behavioral tracking)

2.3 Receipt & OCR Data

Redeema's receipt-scanning feature is used primarily in Kickback campaigns (where a business returns a percentage of a qualifying purchase to an organization) and in any receipt-based campaign. When you scan a receipt in the Redeema app:

  • Image processing. The receipt image is temporarily stored on secure AWS S3 servers and sent to our third-party OCR provider, Google (Gemini), which extracts specific fields: Merchant Name, Purchase Date, and Total Amount.
  • Field limitation. Sensitive fields such as partial card numbers, signatures, or personal identifiers are not used for validation and are disregarded.
  • Duplicate-prevention hash. Redeema stores a one-way cryptographic hash (SHA-256) of each receipt so the same receipt cannot be redeemed more than once. The hash does not reveal the receipt's contents and is retained even after the image is deleted.
  • Image deletion. Once validation is complete, the original receipt image is deleted from active servers; only the duplicate-prevention hash and anonymized transactional metadata are retained.
  • No sale. Redeema does not sell or share individual receipt data with any third party, except the OCR provider acting solely to perform validation.

Processor disclosure: OCR is performed by Google (Gemini), disclosed as a subprocessor. Redeema does not use Amazon Textract or Amazon Rekognition.

3. How We Use Your Information

We use collected data solely to operate and improve the Redeema platform:

  • Create and authenticate user and organization accounts
  • Process campaign participation and attribute contributions or entries to the correct participant, member, or organization — including attribution through shared campaign links
  • Validate Kickback receipts and prevent duplicate or fraudulent submissions
  • Generate and deliver tamper-evident audit records and financial reports
  • Send transactional communications: payment confirmations, campaign updates, entry receipts, and winner notifications
  • Detect and prevent fraudulent activity, duplicate entries, and abuse
  • Comply with applicable law, including tax reporting and sweepstakes regulations
  • Improve platform performance and resolve technical issues

We do NOT use your data for cross-context behavioral advertising, sale to data brokers, or any purpose beyond operating and improving Redeema.

4. Children's Privacy & Minor Participants

Redeema is not directed to children under 13, and we do not knowingly collect personal information directly from any individual under 13. For organizations that manage minor participants (youth sports leagues, schools, K-12 programs), the following applies to all minors, including those aged 13–17:

  • All participant data for minors is entered exclusively by authorized organization administrators — never collected directly from the minor.
  • Data is limited to: first name, last name, group assignment, and the Parent/Guardian's name and email address for communications.
  • Organization administrators represent and warrant that they have obtained verifiable parental consent before submitting any minor's information, for minors of any age under 18.
  • Minor participant pages (Member Pages) are non-indexed, non-discoverable, and accessible only via a private, unique URL shared by the organization.
  • We recommend organizations set all groups containing minors to PRIVATE in Group Settings.
  • If Redeema learns that a minor's information was collected without required parental consent, we will delete it promptly.

To report a concern or request deletion of a minor's data, contact legal@redeema.io.

5. Social Login

If you register or log in via Apple ID or Google:

  • We receive your name, email address, and profile picture (as permitted by those platforms), used solely to create and authenticate your Redeema account.
  • We do not post to your social media accounts.
  • Apple "Hide My Email" is fully supported — we store only the masked relay address provided by Apple.
  • You may revoke access at any time through your Apple or Google security settings.

6. How We Share Your Information

Redeema does not sell, rent, or trade personal information. We share data only as described below.

6.1 Service Providers (Data Processors)

We share information with trusted vendors who process data solely to provide services to Redeema:

  • Amazon Web Services (AWS) — encrypted cloud hosting, receipt-image storage, and notifications (SNS/SES).
  • Google — OCR processing via Gemini for receipt validation, and aggregate, anonymized analytics via Google Analytics.
  • Stripe — PCI-DSS compliant payment processing. Stripe Connect facilitates payouts to organizations and holds saved payment methods, including business payment methods for Kickback.

All service providers are contractually prohibited from using your data for any purpose other than providing services to Redeema. Full list: redeema.io/subprocessors

6.2 Legal Disclosure

We may disclose personal data if required by law, court order, or government authority, or when necessary to protect the rights, property, or safety of Redeema, our users, or the public.

6.3 Business Transfers

In a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, with notice provided as required by law.

7. Data Retention

  • Account Data: retained while your account is active; deleted within 30 days of a verified closure request, subject to legal exceptions.
  • Financial & Transaction Records: retained for 7 years to comply with tax, audit, and Stripe reconciliation requirements.
  • Tamper-Evident Participation Logs: retained in append-only format to preserve the SHA-256 audit chain. Deletion requests may be declined where removal would compromise a financial audit trail.
  • Receipt Images: deleted from active servers upon completion of OCR validation.
  • Receipt Duplicate-Prevention Hashes: retained to prevent reuse of a receipt across campaigns. A hash cannot be reversed to reconstruct the receipt.
  • OCR Metadata: retained in anonymized, aggregated form for analytics — not linked to any individual user.

8. Security

Redeema implements industry-standard security measures appropriate to the sensitivity of the data we process:

  • Encryption in transit (TLS 1.2+) and at rest (AWS KMS)
  • Role-based access controls — only authorized platform roles may access sensitive reports
  • PCI-DSS compliance via Stripe (Redeema maintains SAQ-A certification annually)
  • Tamper-evident audit chain: financial participation records secured with SHA-256 hash chaining — records cannot be altered or deleted without detection
  • Bot detection and anti-fraud controls on all entry and receipt-scanning points

No system is completely secure. If you believe your account or data has been compromised, contact security@redeema.io.

9. Cookies & Tracking Technologies

We use the following technologies:

  • Essential Cookies: required for authentication, session management, and platform security.
  • Analytics (Google Analytics): aggregate, anonymized usage data. No cross-site behavioral profiling.
  • AWS CloudWatch: server-side performance and error monitoring — not user-facing tracking.

We do not use third-party advertising cookies or tracking pixels that follow your activity across unrelated websites.

10. Your Privacy Rights

Regardless of your state or territory of residence, Redeema provides the following rights to all users:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update inaccurate information via your profile or by contacting us.
  • Deletion: request deletion of your account and associated data, subject to legal retention obligations.
  • Opt-Out of Marketing: unsubscribe from promotional communications at any time. Transactional messages are not affected.

10.1 California Residents (CCPA)

Redeema does not 'sell' or 'share' personal information for cross-context behavioral advertising or monetary consideration. California residents have rights to know, delete, and opt out of sale. Contact: legal@redeema.io

10.2 Puerto Rico (Ley 81-2012)

Redeema complies with Puerto Rico's Digital Commerce Act and applicable data-protection obligations, including notification of security breaches within 72 hours of discovery.

11. Data Transfers

Redeema operates primarily within the United States. By using our platform, you consent to the processing and storage of your data on servers located in the United States, which may have different data protection standards than your country of residence.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, legal requirements, or data practices. We will notify you of material changes via:

  • In-app notification within the Redeema platform
  • Email to your registered address

Continued use of the platform after the effective date of any update constitutes acceptance of the revised Policy.

14. Contact Us

Redeema, LLC

Canóvanas, Puerto Rico

Privacy & Legal: legal@redeema.io

Security Reports: security@redeema.io

Subprocessor List: redeema.io/subprocessors

© 2026 Redeema LLC. All rights reserved.