Last updated: 21 September 2026
This Privacy Policy explains how Setia Rewards collects, uses, and protects information shared by Merchants and their customers while using our platform.
We collect: (a) Merchant business and staff account information (name, email, phone number, encrypted password); (b) customer names and phone numbers registered via outlet QR scans; and (c) stamp transaction and reward redemption records.
Data is used solely to operate the core functions of the Service — verifying account identity, tracking stamp card progress, issuing and redeeming vouchers, and helping Merchants understand their customers' visit patterns.
We do not sell or share your data with third parties for marketing purposes. When payment integration (e.g. AffinPay) is enabled in the future, payment information will be processed directly by that gateway provider under their own privacy policy.
We use a session cookie to maintain login state, and one convenience cookie (last phone number used) to speed up the customer stamp check-in process. No third-party advertising tracking cookies are used.
Passwords are stored in encrypted hashed form. Access to Merchant data is restricted by role-based access so staff can only access the functions they are permitted to use.
Data is retained for as long as the Merchant account remains active. Merchants may request data deletion by emailing us, subject to record-keeping requirements for audit or legal purposes.
You have the right to request access to, correction of, or deletion of your personal information. Please contact us via our Contact Us page to make such a request.
This Privacy Policy may be updated from time to time. The "Last updated" date above reflects the current version of this policy.