PointClub Loyalty Points System
Last Updated: 1 February 2026
PointClub ("we", "us", "our") operates the PointClub and PointClub Merchant mobile applications (the "Apps") and associated backend services. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our loyalty points platform.
PointClub is operated from Pakistan and primarily serves businesses and consumers within Pakistan. By using our Apps, you agree to the collection and use of information as described in this policy.
When you create a PointClub customer account, we collect:
When you register a business on PointClub Merchant, we collect:
Merchant owners may add staff members. We collect:
When loyalty points are earned or redeemed, we record:
| Purpose | Data Used |
|---|---|
| Account creation and authentication | Name, email, phone, password |
| Loyalty points earning and redemption | Transaction data, enrollment data |
| QR code generation and validation | Enrollment ID, cryptographic nonces |
| Merchant branding and loyalty card display | Logo, brand colours, business name |
| Staff management and access control | Staff name, phone, role, permissions |
| SMS notifications and OTP verification | Phone number |
| Security monitoring and fraud prevention | IP address, user agent, audit logs |
| Business analytics and reporting | Aggregated transaction and points data |
| Personalised offers and promotions | Transaction history, enrollment data, points balance |
| Improving pricing and service features | Aggregated usage patterns and transaction trends |
| Targeted advertising and promotional communications | Customer preferences, merchant enrollment data, transaction patterns |
All data is stored on Amazon Web Services (AWS) infrastructure in the Asia Pacific (Mumbai) — ap-southeast-1 region. This includes:
| Data Type | Retention Period |
|---|---|
| Customer and merchant accounts | Until account deletion is requested |
| Transaction records | Retained indefinitely for accounting and dispute resolution |
| Enrollment records | Until cancelled by the customer |
| Audit logs (active) | 30 days in primary database |
| Audit logs (archive) | Archived to cold storage indefinitely for compliance |
| OTP codes | 5–10 minutes (automatically deleted) |
| QR code nonces | 5 minutes (automatically deleted) |
| Merchant logos | Until replaced or account deleted |
| Staff accounts | Until deleted by the merchant owner |
When you enrol in a merchant's loyalty programme, that merchant can see your:
Merchants cannot see your activity with other merchants.
We use the following third-party services to operate PointClub:
We do not share, sell, or rent your personal information to any other third parties for their marketing purposes.
We may disclose your information if required by law, court order, or government authority under the laws of Pakistan, including but not limited to the Prevention of Electronic Crimes Act 2016 (PECA) and any applicable data protection regulations.
You have the right to:
We will respond to your request within 30 days.
PointClub is not intended for children under the age of 18. We do not knowingly collect personal information from minors. If you believe a child has provided us with personal data, please contact us immediately at support@pointclub.pk and we will delete such information.
We send SMS messages to Pakistani mobile numbers (+92) for:
These are transactional messages essential for account security. Standard SMS rates from your mobile carrier may apply.
Our Apps do not use browser cookies. We store the following data locally on your device using secure local storage:
All locally stored data is cleared when you log out of the App.
Your data is primarily stored in the AWS Asia Pacific (Mumbai) region. While AWS may process data globally for infrastructure management, your personal data remains within the AWS ap-southeast-1 region. By using PointClub, you consent to the storage of your data in India-based AWS data centres, which is the nearest AWS region to Pakistan.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the App or via email. The "Last Updated" date at the top of this policy indicates when it was last revised.
This Privacy Policy is governed by the laws of Pakistan, including the Prevention of Electronic Crimes Act 2016 (PECA) and any future data protection legislation enacted in Pakistan.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: