Privacy Policy

PointClub Loyalty Points System

Last Updated: 1 February 2026

1. Introduction

PointClub ("we", "us", "our") operates the PointClub and PointClub Merchant mobile applications (the "Apps") and associated backend services. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our loyalty points platform.

PointClub is operated from Pakistan and primarily serves businesses and consumers within Pakistan. By using our Apps, you agree to the collection and use of information as described in this policy.

2. Information We Collect

2.1 Customer Information

When you create a PointClub customer account, we collect:

2.2 Merchant Information

When you register a business on PointClub Merchant, we collect:

2.3 Staff Information

Merchant owners may add staff members. We collect:

2.4 Transaction Data

When loyalty points are earned or redeemed, we record:

2.5 Device and Usage Data

2.6 Information We Do NOT Collect

3. How We Use Your Information

PurposeData Used
Account creation and authenticationName, email, phone, password
Loyalty points earning and redemptionTransaction data, enrollment data
QR code generation and validationEnrollment ID, cryptographic nonces
Merchant branding and loyalty card displayLogo, brand colours, business name
Staff management and access controlStaff name, phone, role, permissions
SMS notifications and OTP verificationPhone number
Security monitoring and fraud preventionIP address, user agent, audit logs
Business analytics and reportingAggregated transaction and points data
Personalised offers and promotionsTransaction history, enrollment data, points balance
Improving pricing and service featuresAggregated usage patterns and transaction trends
Targeted advertising and promotional communicationsCustomer preferences, merchant enrollment data, transaction patterns
Advertising and Offers: We may use your transaction history, enrolled merchants, points balance, and general usage patterns to deliver personalised offers, promotions, and advertisements within the Apps. We do not sell your personal information to third-party advertisers. You can opt out of promotional communications at any time via the App settings or by contacting us.

4. Data Storage and Security

4.1 Where We Store Data

All data is stored on Amazon Web Services (AWS) infrastructure in the Asia Pacific (Mumbai) — ap-southeast-1 region. This includes:

4.2 Security Measures

5. Data Retention

Data TypeRetention Period
Customer and merchant accountsUntil account deletion is requested
Transaction recordsRetained indefinitely for accounting and dispute resolution
Enrollment recordsUntil cancelled by the customer
Audit logs (active)30 days in primary database
Audit logs (archive)Archived to cold storage indefinitely for compliance
OTP codes5–10 minutes (automatically deleted)
QR code nonces5 minutes (automatically deleted)
Merchant logosUntil replaced or account deleted
Staff accountsUntil deleted by the merchant owner

6. Data Sharing

6.1 With Merchants

When you enrol in a merchant's loyalty programme, that merchant can see your:

Merchants cannot see your activity with other merchants.

6.2 With Service Providers

We use the following third-party services to operate PointClub:

We do not share, sell, or rent your personal information to any other third parties for their marketing purposes.

6.3 Legal Requirements

We may disclose your information if required by law, court order, or government authority under the laws of Pakistan, including but not limited to the Prevention of Electronic Crimes Act 2016 (PECA) and any applicable data protection regulations.

7. Your Rights

You have the right to:

We will respond to your request within 30 days.

8. Children's Privacy

PointClub is not intended for children under the age of 18. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us immediately at support@pointclub.pk and we will delete such information.

9. SMS Communications

We send SMS messages to Pakistani mobile numbers (+92) for:

These are transactional messages essential for account security. Standard SMS rates from your mobile carrier may apply.

10. Cookies and Local Storage

Our Apps do not use browser cookies. We store the following data locally on your device using secure local storage:

All locally stored data is cleared when you log out of the App.

11. International Data Transfers

Your data is primarily stored in the AWS Asia Pacific (Mumbai) region. While AWS may process data globally for infrastructure management, your personal data remains within the AWS ap-southeast-1 region. By using PointClub, you consent to the storage of your data in India-based AWS data centres, which is the nearest AWS region to Pakistan.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the App or via email. The "Last Updated" date at the top of this policy indicates when it was last revised.

13. Governing Law

This Privacy Policy is governed by the laws of Pakistan, including the Prevention of Electronic Crimes Act 2016 (PECA) and any future data protection legislation enacted in Pakistan.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: