Legal
Privacy Policy
Effective Date: July 18, 2026
1. Who We Are & Scope
Redeema, LLC ("Redeema," "we," "us," or "our") is a FinTech platform incorporated in Puerto Rico that operates a Community Operating System — enabling organizations such as sports leagues, graduating classes, schools, and faith communities to manage dues, fundraising campaigns, events, sweepstakes, memberships, and business-sponsored Kickback programs. This Privacy Policy governs all personal data collected through our mobile applications, web portals, and business-facing tools across Puerto Rico and the United States.
- End users of the Redeema mobile application and web platform
- Organization administrators (leagues, schools, classes, faith communities)
- Business partners who create and fund Kickback campaigns
- Parents and guardians who interact on behalf of minor participants
We adhere to the principle of Privacy by Design: data collection is limited strictly to what is necessary for platform functionality.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration: name, email address, phone number.
- Organization profile: organization name, logo, administrator contact information, and EIN (for business accounts).
- Participant data entered by authorized administrators: first name, last name, group assignment, and Parent/Guardian name and email (for minor participants).
- Payment initiation: processed entirely by Stripe. Redeema does not store card numbers, bank account numbers, or full payment credentials for any user or organization.
- Business payment method for Kickback: a sponsoring business saves a payment method through Stripe's secure setup process so approved kickbacks can be charged off-session. This credential is held by Stripe, not by Redeema.
- Communications: messages submitted via support channels or contact forms.
2.2 Information Collected Automatically
- Device identifiers and IP addresses (used for fraud prevention and audit-log integrity)
- Session data and usage logs (pages visited, actions taken, timestamps)
- Referral and attribution data — when a campaign is shared, a deeplink may carry a member identifier so participation can be attributed to the member who shared it. Links opened from an organization page carry no member attribution.
- AWS CloudWatch performance and error logs
- Google Analytics aggregate traffic data (no cross-site behavioral tracking)
2.3 Receipt & OCR Data
Redeema's receipt-scanning feature is used primarily in Kickback campaigns (where a business returns a percentage of a qualifying purchase to an organization) and in any receipt-based campaign. When you scan a receipt in the Redeema app:
- Image processing. The receipt image is temporarily stored on secure AWS S3 servers and sent to our third-party OCR provider, Google (Gemini), which extracts specific fields: Merchant Name, Purchase Date, and Total Amount.
- Field limitation. Sensitive fields such as partial card numbers, signatures, or personal identifiers are not used for validation and are disregarded.
- Duplicate-prevention hash. Redeema stores a one-way cryptographic hash (SHA-256) of each receipt so the same receipt cannot be redeemed more than once. The hash does not reveal the receipt's contents and is retained even after the image is deleted.
- Image deletion. Once validation is complete, the original receipt image is deleted from active servers; only the duplicate-prevention hash and anonymized transactional metadata are retained.
- No sale. Redeema does not sell or share individual receipt data with any third party, except the OCR provider acting solely to perform validation.
Processor disclosure: OCR is performed by Google (Gemini), disclosed as a subprocessor. Redeema does not use Amazon Textract or Amazon Rekognition.
3. How We Use Your Information
We use collected data solely to operate and improve the Redeema platform:
- Create and authenticate user and organization accounts
- Process campaign participation and attribute contributions or entries to the correct participant, member, or organization — including attribution through shared campaign links
- Validate Kickback receipts and prevent duplicate or fraudulent submissions
- Generate and deliver tamper-evident audit records and financial reports
- Send transactional communications: payment confirmations, campaign updates, entry receipts, and winner notifications
- Detect and prevent fraudulent activity, duplicate entries, and abuse
- Comply with applicable law, including tax reporting and sweepstakes regulations
- Improve platform performance and resolve technical issues
We do NOT use your data for cross-context behavioral advertising, sale to data brokers, or any purpose beyond operating and improving Redeema.
4. Children's Privacy & Minor Participants
Redeema is not directed to children under 13, and we do not knowingly collect personal information directly from any individual under 13. For organizations that manage minor participants (youth sports leagues, schools, K-12 programs), the following applies to all minors, including those aged 13–17:
- All participant data for minors is entered exclusively by authorized organization administrators — never collected directly from the minor.
- Data is limited to: first name, last name, group assignment, and the Parent/Guardian's name and email address for communications.
- Organization administrators represent and warrant that they have obtained verifiable parental consent before submitting any minor's information, for minors of any age under 18.
- Minor participant pages (Member Pages) are non-indexed, non-discoverable, and accessible only via a private, unique URL shared by the organization.
- We recommend organizations set all groups containing minors to PRIVATE in Group Settings.
- If Redeema learns that a minor's information was collected without required parental consent, we will delete it promptly.
To report a concern or request deletion of a minor's data, contact legal@redeema.io.
7. Data Retention
- Account Data: retained while your account is active; deleted within 30 days of a verified closure request, subject to legal exceptions.
- Financial & Transaction Records: retained for 7 years to comply with tax, audit, and Stripe reconciliation requirements.
- Tamper-Evident Participation Logs: retained in append-only format to preserve the SHA-256 audit chain. Deletion requests may be declined where removal would compromise a financial audit trail.
- Receipt Images: deleted from active servers upon completion of OCR validation.
- Receipt Duplicate-Prevention Hashes: retained to prevent reuse of a receipt across campaigns. A hash cannot be reversed to reconstruct the receipt.
- OCR Metadata: retained in anonymized, aggregated form for analytics — not linked to any individual user.
8. Security
Redeema implements industry-standard security measures appropriate to the sensitivity of the data we process:
- Encryption in transit (TLS 1.2+) and at rest (AWS KMS)
- Role-based access controls — only authorized platform roles may access sensitive reports
- PCI-DSS compliance via Stripe (Redeema maintains SAQ-A certification annually)
- Tamper-evident audit chain: financial participation records secured with SHA-256 hash chaining — records cannot be altered or deleted without detection
- Bot detection and anti-fraud controls on all entry and receipt-scanning points
No system is completely secure. If you believe your account or data has been compromised, contact security@redeema.io.
10. Your Privacy Rights
Regardless of your state or territory of residence, Redeema provides the following rights to all users:
- Access: request a copy of the personal data we hold about you.
- Correction: update inaccurate information via your profile or by contacting us.
- Deletion: request deletion of your account and associated data, subject to legal retention obligations.
- Opt-Out of Marketing: unsubscribe from promotional communications at any time. Transactional messages are not affected.
10.1 California Residents (CCPA)
Redeema does not 'sell' or 'share' personal information for cross-context behavioral advertising or monetary consideration. California residents have rights to know, delete, and opt out of sale. Contact: legal@redeema.io
10.2 Puerto Rico (Ley 81-2012)
Redeema complies with Puerto Rico's Digital Commerce Act and applicable data-protection obligations, including notification of security breaches within 72 hours of discovery.
11. Data Transfers
Redeema operates primarily within the United States. By using our platform, you consent to the processing and storage of your data on servers located in the United States, which may have different data protection standards than your country of residence.
12. Third-Party Links
Our platform may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party services you access through Redeema.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, legal requirements, or data practices. We will notify you of material changes via:
- In-app notification within the Redeema platform
- Email to your registered address
Continued use of the platform after the effective date of any update constitutes acceptance of the revised Policy.
14. Contact Us
Redeema, LLC
Canóvanas, Puerto Rico
Privacy & Legal: legal@redeema.io
Security Reports: security@redeema.io
Subprocessor List: redeema.io/subprocessors
© 2026 Redeema LLC. All rights reserved.
5. Social Login
If you register or log in via Apple ID or Google: