Spendium — Privacy Policy
Effective date: [DATE] · Version 1.0
Before the legal detail, here is what this policy means in practice:
- We collect purchase data — stores, amounts, and the individual products on your receipt — to verify ethical purchasing activity, award points, and build product-level ethical ratings. Nothing else.
- We do not sell your data. We do not share it with the stores you shop at. Retailers never learn who scanned their QR code.
- Receipt photos are read once and then deleted, always within 24 hours. We do not retain images of your financial documents.
- We do not connect to your bank account. Spendium has no access to your financial institution.
- Purchase history can reveal sensitive things about you. We treat it accordingly — it is never used for profiling, advertising, or sharing with third parties.
- After 30 days, your purchases stop being linked to you. We keep the shopping data itself, because that is what the ratings are built from, but the connection to you is destroyed rather than merely hidden — after that point we cannot tell whose it was, and neither can anyone else.
- You can delete your purchase history independently of your account, at any time before then.
1. Who We Are
Spendium is an ethical purchasing game operated by Human Flourishing (“HF”, “we”, “us”). It allows players to log purchases at physical stores, survey those stores against ethical criteria, contribute to community-generated ratings, and earn points for doing so. HF’s mission is to improve real-world outcomes by rewarding ethical behaviour — for everyone, forever.
Spendium is a game about physical commerce. Online-only purchases are outside the scope of the game’s core mission and are treated differently to in-store purchases, as described in Section 3.
For privacy enquiries, contact us at: privacy@[domain]
2. What We Collect and Why
2.1 Account Data
When you create an account we collect:
- Email address — used for login, security notices, survey delivery, and optional communications.
- Username — your public display name within the game. It does not have to be your real name.
- Password (hashed; we never store the plaintext).
- Membership tier — whether you are a free or paid member.
- Date of account creation.
We do not require your real name, phone number, date of birth, or any government identifier to use Spendium.
2.2 Purchase Data
When you log a purchase, we collect:
- Store identifier — the store where the purchase was made, either from a QR code scan, a receipt, or your self-report.
- Purchase amount — self-reported by you, or extracted from a receipt photo.
- Purchase date and time — to establish the timing of your activity and award time-based bonuses.
- Logging method — whether the purchase was logged via QR scan, receipt photo, or trust-based self-report. This determines the points multiplier applied.
- Itemised product data — when you provide a receipt photo, we extract the individual line items: product names, quantities, and prices. This data is used to award per-product points and to contribute to product-level ethical ratings within the game.
2.3 Receipt Photos
If you choose to photograph your receipt to verify a purchase:
- The image is processed to extract the store name, date, total amount, and individual line items (product names, quantities, and prices).
- The image is deleted within 24 hours of processing. We do not retain receipt photos.
- Extracted data (store, date, amount, and itemised products) is retained as purchase data per Section 2.2.
- Receipt processing may be performed by a third-party OCR service. Where this is the case, the image is transmitted securely and the service is contractually prohibited from retaining or using it for any other purpose.
2.4 QR Code Scan Data
When you scan a store’s HF QR code:
- The store ID encoded in the QR code is recorded.
- The time and date of the scan is recorded.
- No data is transmitted to the store. The store does not learn that you scanned their code, who you are, or any information about your account.
2.5 Gameplay Data
- Survey responses — your yes/no answers to HF criteria questions about stores. Stored linked to your account ID for deduplication and points purposes, but aggregated before public display. Your individual answers are never attributed to you by name.
- Evidence submissions — links, documents, or references you submit to support store ratings. Publicly visible and attributed to your username.
- Usefulness votes and flags — your votes on evidence submitted by others, and flags you raise. Stored for integrity purposes; not displayed individually.
- Points balance and transaction history — a ledger of how you earned points within the game.
2.6 Location Data
Spendium does not require or request your GPS location. We do not track where you are.
If you choose to search for nearby stores within the app, your approximate location is used to return results. It is not logged, stored, or associated with your account.
2.7 Technical Data
- IP address — collected at login for security purposes (rate limiting, fraud detection). Not used for tracking or advertising.
- Device and browser type — collected for compatibility and debugging.
- Session data — a session token stored in a secure cookie to keep you logged in.
- Usage logs — pages visited, actions taken, and timestamps. Used in aggregate to improve the platform. Not sold or shared.
2.8 What We Do Not Collect
- Bank account details, credit or debit card numbers, or any data from your financial institution.
- Race, ethnicity, religion, gender, or sexual orientation.
- Precise geolocation or movement history.
- Data about your purchases outside Spendium.
3. How We Use Your Data
We use the data we collect exclusively to:
- Operate the game — verify purchase activity, calculate store and product ratings, award points, and surface relevant local stores.
- Build product-level ethical ratings — itemised purchase data is aggregated and anonymised to generate ratings for individual products and brands. These ratings are published publicly and are intended to create accountability for manufacturers and retailers. No individual player’s purchasing choices are ever attributed or identifiable in published ratings.
- Deliver surveys — send post-purchase survey emails so you can rate the store you just visited.
- Prevent abuse — detect duplicate purchase logs, manipulated amounts, and fraudulent point claims.
- Communicate with you — send account security emails and, if you opt in, product updates.
- Improve the platform — analyse anonymised usage patterns to fix bugs and improve features.
- Comply with legal obligations — where applicable law requires us to retain or disclose data.
We do not use your data for advertising, behavioural profiling, or any purpose not listed above.
4. Purchase Data — Heightened Protections
Purchase history is sensitive. A record of where someone shops — and what they buy — can reveal religious beliefs, health conditions, political affiliations, dietary choices, and financial circumstances. Itemised product data amplifies this sensitivity considerably. We apply a higher standard of protection to purchase and product data than to other gameplay data:
- Purchase data is never sold to any party, under any circumstances.
- Purchase data is never shared with the stores featured in Spendium, with advertisers, or with data brokers.
- Purchase data is never used to build a profile of you for any purpose other than operating the game.
- Aggregate statistics derived from purchase and product data are published without any individual attribution.
- You can delete your purchase history at any time — independently of deleting your account — via account settings. Deleted purchases are removed from your record; aggregate store ratings derived from them are not retroactively altered.
5. Store Data and Third Parties
5.1 Store Profiles
Spendium holds data about stores and brands. This includes store names, locations, categories, and community ratings. Much of this information is publicly available. Community ratings are aggregate expressions of player opinion, clearly presented as such.
Stores that participate in Spendium by displaying a QR code do not receive player data in return. Participation gives a store a public HF rating and visibility within the app — nothing more.
5.2 Third-Party Integrations
If Spendium integrates with point-of-sale systems (e.g. Square, Shopify) in future stages, we will update this policy to describe the data exchanged. Any such integration will be limited to verifying transaction amounts for points purposes and will not give those services access to your Spendium account or profile.
6. Sharing and Disclosure
We do not sell your personal data. We share it only in the following limited circumstances:
- Service providers — we use third-party services to host the platform, process receipts, send emails, and monitor for security threats. These providers process data on our behalf under strict data processing agreements and are not permitted to use your data for their own purposes.
- Legal obligations — we may disclose data if required by a court order, subpoena, or applicable law. We will notify you if we receive such a request unless prohibited by law from doing so.
- Business transfers — if HF merges with or is acquired by another organisation, your data may transfer as part of that transaction. We will notify you in advance and you will have the opportunity to delete your account.
- With your consent — we will not share your data for any other purpose without asking you first.
7. Data Retention
- Account data — retained for as long as your account is active, plus 30 days after deletion to allow for recovery requests.
- Purchase records — retained for 30 days, then permanently anonymised so they can no longer be linked to you. You can delete your purchase history at any time before then via account settings. All purchase records are deleted when you delete your account.
- Receipt photos — deleted within 24 hours of processing, regardless of account status.
- Survey responses — retained indefinitely. When you delete your account, individual responses are anonymised so they can no longer be linked to you; the ratings they contribute to are not retroactively altered.
- Technical logs — retained for 90 days, then automatically purged.
- Evidence submissions — retained after account deletion in anonymised form (your username is replaced with “[deleted]”).
8. Your Rights
You have the following rights regarding your personal data. To exercise any of them, contact us at privacy@[domain].
- Access — you can request a copy of the personal data we hold about you, including your full purchase history.
- Correction — you can correct inaccurate account data at any time via account settings.
- Deletion of purchase history — you can delete your purchase history independently of your account at any time via account settings.
- Full account deletion — you can delete your account and all associated personal data at any time. Some anonymised data may be retained as described in Section 7.
- Portability — you can request an export of your personal data, including purchase records, in a machine-readable format.
- Objection — you can object to any use of your data beyond what is necessary to operate the game.
- Withdrawal of consent — where we rely on consent (e.g. optional communications), you can withdraw it at any time.
We will respond to rights requests within 30 days. If you are unhappy with our response, you may lodge a complaint with the relevant data protection authority in your jurisdiction.
9. Security
- Passwords are hashed using a modern, slow hashing algorithm (bcrypt or equivalent). We never store plaintext passwords.
- Data is encrypted in transit using TLS 1.2 or higher.
- Purchase data and receipt images are encrypted at rest.
- Receipt images are stored in an isolated environment with access restricted to the processing pipeline only. No human employee can access your receipt images during normal operations.
- Access to production data is restricted to authorised personnel only and is logged.
- We conduct regular security reviews and act on findings promptly.
In the event of a data breach that affects your personal data — and in particular any breach involving purchase or receipt data — we will notify you within 72 hours of becoming aware of it, consistent with applicable law.
10. Cookies and Tracking
We use the minimum cookies necessary to operate the service:
- Session cookie — keeps you logged in during a browser session. Expires when you close your browser or log out.
- Persistent login cookie — if you choose “remember me”, a secure token is stored for up to 30 days.
- CSRF token — a security cookie that prevents cross-site request forgery attacks.
We do not use advertising cookies, third-party tracking cookies, or analytics cookies that send data to external parties. We do not participate in cross-site tracking.
11. Minors
Spendium is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from minors. Given the financial nature of purchase data, we take particular care to ensure minors are not using the service. If we become aware that a minor has created an account, we will delete the data and the account immediately. If you believe a minor has created an account, please contact us at privacy@[domain].
12. Changes to This Policy
We will post any changes to this policy on this page with an updated effective date. For material changes — particularly any changes to how purchase data or receipt images are handled — we will notify you by email at least 14 days before the change takes effect. Continued use of Spendium after the effective date constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions or to exercise your rights:
- Email: privacy@[domain]
- Post: Human Flourishing, [Address]
We aim to respond to all enquiries within 5 business days.