Rewards Pro ← Back to Rewards Pro

Privacy, in plain words

What Rewards Pro handles—and why.

This policy explains how Cambridge TCG Limited handles data across rewardspro.io, the embedded merchant application, Shopify storefront surfaces, and merchant-enabled integrations.

Last updated 23 July 2026
Operator

Cambridge TCG Limited, company number 15680297.

Core promise

We do not sell personal data for money or use Shopify merchant or customer data to train AI models.

1. Scope and roles

Rewards Pro is operated by Cambridge TCG Limited, an active company registered in England and Wales under company number 15680297. Our registered office is 60 Tottenham Court Road, Suite 4583a, Fitzrovia, London, W1T 2EW, United Kingdom.

This policy covers visitors to rewardspro.io, merchants and their staff who install or operate Rewards Pro, and shoppers whose data is processed through a participating merchant’s loyalty programme.

Merchants need their own privacy notice. Rewards Pro supports a merchant’s loyalty programme; it does not replace the merchant’s explanation of how that store uses shopper data or obtains any marketing consent it needs.

Our role depends on the activity

For merchant account administration, direct support, service security, and our own product operations, Cambridge TCG Limited generally decides why and how data is used and acts as a controller. When we process a merchant’s shopper and order data to run that merchant’s selected loyalty rules, communications, or integrations, we generally act as that merchant’s processor or service provider. The facts and applicable law determine the role in each case.

2. Data we handle

Audience Data categories Main source
Website visitors Request and device metadata ordinarily processed by hosting, DNS, security, and email-obfuscation services; information you include in a direct email. Your browser, Cloudflare, and your message.
Merchants and staff Shopify user and store identifiers; name, email, role, locale, store domain, name, URL, currency and timezone; programme settings, tiers, campaigns, plan, usage, billing status, support messages, and integration configuration. Shopify and information entered in Rewards Pro.
Merchant shoppers Shopify customer ID; email, name, phone, birthday, tags, account and marketing status when present; order, product, currency, spend and refund records; points, cashback, store credit, tiers, subscriptions, reward and participation history; gift-recipient details and personal messages when a gift is configured; customer segments and recommendations; and email delivery, open, click, complaint, or unsubscribe events. The merchant’s Shopify store, Rewards Pro activity, and merchant-enabled providers.
Technical records Session, webhook and external-platform identifiers; event times and status; diagnostics, security records, request metadata, device/browser information, performance traces, and sampled replay data when the relevant monitoring tool is configured. Shopify, your browser, our application, and our infrastructure providers.

Shopify permissions can make additional protected customer data available to the application. Rewards Pro aims to retain only the fields needed for the configured service. Its core loyalty records do not intentionally store complete payment-card numbers or full shipping and billing addresses. Shopify, not Rewards Pro, handles the merchant’s app-billing card details.

Shopify store and account identifiers and the configuration required for a selected feature are necessary to install and operate Rewards Pro. Without them, we cannot provide that service. Other fields and integrations are optional unless stated otherwise.

3. Why we use data and the applicable basis

Purpose Role and UK GDPR basis
Install, authenticate, configure, and bill for the merchant application. Controller: contract and steps requested before a contract.
Administer merchant accounts and answer support enquiries that are not necessary to perform the contract. Controller: legitimate interests in supporting users and operating the service responsibly.
Serve and secure rewardspro.io and answer website enquiries. Controller: legitimate interests in operating a secure website and responding; requested pre-contract steps where an enquiry concerns purchasing Rewards Pro.
Sync customers, orders and refunds; calculate points, cashback and tiers; issue or reconcile rewards; and show loyalty status. Usually processor under the merchant’s instructions. The merchant determines its lawful basis for the shopper relationship.
Run merchant-selected emails, automations, analytics, and connected services. Usually processor under merchant instructions. The merchant is responsible for consent, opt-out, and other lawful-basis requirements for its communications.
Prevent duplicate rewards and abuse; authenticate webhooks; investigate errors; protect accounts; and maintain reliability. Legitimate interests in securing Rewards Pro, merchants, shoppers, and the integrity of reward ledgers. We limit this processing to what is reasonably necessary.
Maintain billing, compliance, complaint, and other records required by law or needed to establish, exercise, or defend legal claims. Legal obligation and legitimate interests in accountable business operations.
Measure product use and performance and improve the merchant experience. Controller: legitimate interests in proportionate service diagnostics. This basis does not replace any separate consent that device-storage or access rules may require.

Rule-based rewards

Rewards Pro automatically calculates balances, tiers, and reward eligibility from order activity and rules chosen by the merchant. Those calculations affect programme benefits. We do not use them to make decisions about credit, employment, insurance, or another matter intended to produce legal or similarly significant effects.

4. Providers, integrations, and disclosure

We use service providers to operate Rewards Pro. The provider used for a particular merchant can depend on configuration and enabled integrations.

Shopify Installation, authentication, APIs, billing, store data, and native commerce surfaces.
Amazon Web Services Database and supporting cloud services; SES email when enabled; Bedrock for requested AI drafting.
Vercel Embedded application hosting, performance telemetry, and optional distributed storage.
Cloudflare Public website hosting, DNS, network security, and email-address protection.
Twilio SendGrid or AWS SES Transactional or merchant-configured email delivery and delivery-event processing.
Sentry Error, performance, reliability, and sampled session-replay monitoring.
Merchant-enabled services Klaviyo and other explicitly connected platforms receive only the data needed for the selected integration.
GitBook Merchant help questions are sent to the documentation assistant only when that tool is used.

We may also disclose data where law requires it, to protect people or the service, or in connection with a corporate transaction subject to appropriate safeguards. We do not sell personal data for money or use Rewards Pro customer data for cross-context behavioural advertising. Measurement and monitoring providers process data for the purposes described in this policy and may also process limited data for their own security, fraud-prevention, legal-compliance, and service administration purposes under their applicable terms.

5. Cookies, telemetry, and session replay

The public website

The rewardspro.io landing pages do not load a first-party advertising or product-analytics script. Cloudflare processes ordinary request metadata and may rewrite displayed email addresses to reduce automated scraping.

The embedded merchant application

Essential Shopify and application session mechanisms keep merchants authenticated and protect requests. Vercel Analytics and Speed Insights measure visits and performance.

When Sentry is configured in production, it receives error and performance information and may sample session replay. Form inputs are configured to be masked, but visible page text and interaction context can still appear in replay or diagnostic records. Merchants should not place unnecessary personal or secret information in free-text fields.

Diagnostic events sent to monitoring providers may include shop or customer identifiers and relevant loyalty or transaction context, such as tier or spend. Application logs may include request headers and submitted request content for diagnostics, security, and reliability. Access is restricted to operational purposes.

The embedded application currently loads the telemetry tools described above when configured. Rewards Pro does not currently provide an in-app analytics preference control. Browser controls may block some non-essential storage or scripts, but may also affect functionality.

6. Marketing, integrations, and AI

Merchant communications

Rewards Pro records Shopify marketing status, unsubscribe, bounce, and complaint signals to support suppression. A merchant decides whether to enable a campaign or integration and remains responsible for its audience, lawful basis, message, and required opt-out route. Rewards Pro does not use Shopify customer data for its own unrelated marketing.

When SendGrid email is enabled, delivery records can include opens and link clicks as well as bounces, complaints, and unsubscribes. Merchants must explain and configure that measurement consistently with their own notice and applicable consent rules.

Connected services

If a merchant connects Klaviyo or another supported service, Rewards Pro can send customer identifiers, contact details, loyalty properties, and selected events to that provider. Disconnecting an integration stops new Rewards Pro transfers; the provider’s own retention and the merchant’s account with that provider still apply.

AI-assisted drafting

A merchant can request AI assistance for email copy. The prompt, existing draft, template type, and limited brand context are sent through Amazon Bedrock to an Anthropic Claude model. Merchants should not put shopper personal data into a prompt. Cambridge TCG Limited does not use Shopify merchant data, customer data, or derived data to train AI or machine-learning models.

7. Retention, redaction, and deletion

We use the following criteria rather than claiming one period fits every record:

  • No fixed automatic expiry currently applies to general merchant configuration, customer loyalty, order, and reward records. They are kept while the merchant uses Rewards Pro. An uninstall does not itself start a reliable automatic deletion timer: records remain until a shop cleanup or valid redaction request is completed, subject to a documented legal-retention need.
  • Expired online authentication sessions are scheduled for deletion after a 24-hour buffer. Offline or no-expiry sessions are retained until they are no longer needed or the relevant shop cleanup runs.
  • Completed or failed processed billing-webhook records are scheduled for deletion after seven days.
  • Email suppression information may be retained as needed to continue honouring an opt-out, complaint, or delivery block.
  • Billing, compliance, security, dispute, and audit records may be retained for the period required by law or reasonably needed for accountability and legal claims.
  • Provider-held operational logs and backups remain until they are overwritten or deleted under the relevant account, contract, or provider lifecycle, subject to any legal hold. Rewards Pro has not yet published a provider-by-provider schedule; contact us for the current setting relevant to a particular provider and data type.

Shopify sends mandatory customer-data-request and redaction webhooks to Rewards Pro. Our application begins processing those requests, but manual intervention may be required to complete or verify an access, deletion, or anonymisation request. Shopify requires a valid compliance request to be completed within 30 days unless applicable law requires retention. Shoppers should contact the relevant merchant first, or email contact@rewardspro.io for assistance and confirmation.

8. Your data-protection rights

Depending on your location, our role, the purpose, and applicable exemptions, you may have rights to:

  • receive information about processing and access your data;
  • correct inaccurate or incomplete data;
  • request deletion or restriction;
  • receive portable data where the portability right applies;
  • withdraw consent where processing relies on consent; and
  • object to certain processing based on legitimate interests or direct marketing.

If you are a shopper, the merchant running your loyalty programme is usually the best first contact for store-specific data. You can also contact Rewards Pro directly. We may need to verify identity and coordinate with the merchant or Shopify. UK rights requests are normally answered within one calendar month, subject to the extensions and exemptions permitted by law.

Your right to object

You can object to processing based on our legitimate interests by emailing contact@rewardspro.io. You can object to direct marketing at any time. Where a merchant is responsible for the activity, we will route or coordinate the request with that merchant.

9. Data-protection complaints

Send a complaint to contact@rewardspro.io with the subject “Data protection complaint”. Include enough detail for us to identify the merchant, account, or interaction without emailing passwords, access tokens, or full payment details.

We will acknowledge a data-protection complaint within 30 days, investigate it, provide appropriate progress updates, and communicate the outcome without undue delay.

You can also complain to the UK Information Commissioner’s Office. If you live outside the UK, your local data-protection authority may also be able to help.

10. International transfers and security

Rewards Pro’s core AWS services are configured in Sweden, and the current Sentry endpoint is in the European Union. Shopify, Cloudflare, Vercel, SendGrid, GitBook, and merchant-enabled providers may also process data in the UK, EEA, United States, and locations used by their networks. Rewards Pro is completing a provider-by-provider record of the applicable UK transfer safeguards and does not promise that data remains in one country. Contact us for the current destination and safeguard information relevant to your data.

We use measures appropriate to the service and risk, including HTTPS, Shopify-signed request verification, access controls, isolation by shop, secret-management and encryption mechanisms, idempotent event processing, monitoring, and data-reduction in selected logs. No online service can promise absolute security. Please report a suspected data incident immediately to contact@rewardspro.io.

11. Contact and policy changes

Cambridge TCG Limited
Company number 15680297
60 Tottenham Court Road, Suite 4583a
Fitzrovia, London, W1T 2EW
United Kingdom
contact@rewardspro.io

We review this notice when the product, providers, or legal requirements change. The date at the top will change, and we will give additional notice before a material new use where applicable law requires it.

For Shopify’s own handling of data, read Shopify’s privacy policy. For store-specific handling, read the merchant’s privacy notice.