Skip to content

Legal

Privacy policy

How Rebici handles customer and business data, who we share it with, and what we deliberately do not collect.

Last updated: 22 August 2026

Who we are

Rebici is a loyalty platform operated by Prometeuz. In this policy, "we", "us" and "Rebici" mean Prometeuz operating the Rebici service.

You can reach us about anything in this policy at hello@rebicibusiness.com.

What this policy covers

This policy covers the Rebici app for customers, the Rebici Business app for business owners and their employees, and the servers behind both.

It also covers this website, though the website collects almost nothing. It sets no cookies, runs no analytics or advertising trackers, and serves its fonts from our own servers rather than a third party. The contact form does not send anything to us: it opens your own email app with a message prepared, and nothing leaves your device unless you send it yourself.

Our role: controller and processor

Rebici plays two different roles depending on the data, and the distinction matters for who you go to with a request.

For your account itself — how you sign in, your profile, your notification preferences, and the operation and security of the platform — we are the personal information controller. We decide what is collected and why, and requests about that data come to us.

For the loyalty side — your enrollment in a particular business’s program, your balances with that business, and the record of transactions between you and that business — we act as a personal information processor for that business. The business decides what its program does and what its terms are; we run it on their behalf. Requests about a specific loyalty relationship may need to go to that business, and we will help you reach them.

What we collect

We collect only what a loyalty program needs to work. Most customer profile information is optional: you can use Rebici without providing a display name, email address, phone number, date of birth or profile image.

  • Account and authentication data: an account identifier from our authentication provider, the sign-in method you used, and the email address attached to it where you signed in with one.
  • Optional profile information: display name, email address, phone number, date of birth, profile image, notification preferences, and a linked NFC card identifier where you choose to link a physical card.
  • Business information: the business name, logo, category, address, website, social media links and contact details the owner publishes.
  • Branch, employee and device records the owner creates, including employee display names and email addresses. Staff PINs and employee invite codes are never stored in a readable form — we keep only a one-way hash.
  • Loyalty data: which programs you have joined, your stamp counts, point balances and membership periods, and the rewards you have unlocked or redeemed.
  • Technical data needed to deliver the service: the device token used to send you push notifications, and server logs recording requests to our systems.

Loyalty and transaction records

Every action that changes a loyalty balance creates a record. That record includes the business, branch and program, your enrollment, the owner or employee who acted, the device it came from, the transaction type, the eligible purchase amount where a point program was used, the reward involved, the balance before and after, and a timestamp. Each record also carries an idempotency key, which is how a retried request cannot double-grant a balance.

These records are how we can tell you honestly what happened to a balance. They are kept as an immutable history: corrections are recorded as reversals rather than by editing or deleting the original.

A date of birth is only relevant where a business runs birthday rewards, and is never required to use the app.

Why we process it, and on what basis

Under the Data Privacy Act of 2012 (Republic Act No. 10173) we must have a lawful basis for processing your personal information. Ours are the following.

  • To perform our agreement with you: creating and maintaining your account, running the loyalty programs you join, calculating balances, and delivering the notifications those programs depend on.
  • With your consent: the optional profile fields, a date of birth used for birthday rewards, a linked NFC card identifier, and posts from businesses you have chosen to join. You can withdraw consent for these at any time by removing the information or changing your notification preferences.
  • For our legitimate interests, balanced against your rights: preventing fraud and abuse of loyalty balances, keeping audit logs of changes to permissions, employees, devices and programs, securing our systems, and diagnosing faults.
  • To comply with legal obligations, including responding to lawful requests from the National Privacy Commission or other authorities.

Authentication and anonymous accounts

Sign-in is handled through Firebase Authentication, a Google service. Customers can use anonymous sign-in, email and password, Google or Apple. Business owners can use email and password, Google or Apple. We never see or store your password.

Anonymous sign-in exists so you can start using Rebici without handing over personal information. We will periodically prompt you to link a permanent sign-in method, because loyalty data attached only to an anonymous session can be lost with the device.

What businesses can see

A business can see only the customers it has its own relationship with, and only the activity arising from that relationship. One business cannot see another business’s customer relationships, balances or transaction history.

Businesses can see the programs a customer has joined with them, their balances, their transactions with that business, and the total eligible purchases recorded through those programs. They cannot see your activity with any other business, and they cannot see profile information you have not provided.

QR codes

Customer QR codes do not contain personal information. They carry a member code that our servers resolve, so a photographed or screenshotted code exposes nothing about you.

Notifications

We send notifications about stamps and points received, rewards unlocked and redeemed, memberships activated or nearing expiry, loyalty value nearing expiry, and posts from businesses you have joined. Push delivery uses Firebase Cloud Messaging, a Google service, which receives a device token but not the content of your loyalty history.

Notification preferences are yours to change. Push delivery is a channel, not the record: important notifications are kept in your Rebici inbox even if push delivery fails.

Who we share data with

We do not sell your personal information, and we do not share it with advertising networks. We share it only with the business you chose to join, and with the service providers we need to run the platform.

  • The business whose program you joined, limited to that relationship as described above.
  • Google, for Firebase Authentication (sign-in) and Firebase Cloud Messaging (push notifications).
  • MongoDB Atlas, which hosts the database holding accounts, programs and loyalty records.
  • Cloudinary, which stores and serves images such as business logos and loyalty card backgrounds.
  • Railway and Vercel, which host and run our application servers.
  • Authorities and advisers where we are legally required to disclose, or where disclosure is necessary to establish or defend a legal claim.

Where your data is stored

Some of the providers above process data on servers outside the Philippines. Where that happens, we remain accountable for your personal information under Republic Act No. 10173, and we use providers that contractually commit to a comparable standard of protection and security.

How long we keep it

You can delete your account from Settings.

When you do, we erase your account, profile and notification preferences within 30 days. Backup copies are overwritten on our normal backup cycle shortly after.

Loyalty activity records are handled differently. Rather than delete them, we strip them of anything that identifies you and retain them as anonymous transaction history, because the business needs its own record of what it granted and redeemed. Once anonymised, those records can no longer be linked back to you.

Where a business closes its account, its programs end and the enrollments under them are closed. We keep audit records of platform-level actions for as long as we need them for security and dispute handling.

Your rights

The Data Privacy Act gives you rights over your personal information. You can exercise any of them by writing to us.

  • To be informed that your personal information is being collected and processed, and why.
  • To access the personal information we hold about you.
  • To have inaccurate or incomplete information corrected.
  • To object to processing, including withdrawing consent where consent is our basis.
  • To have your information erased or blocked where it is incomplete, outdated, false, unlawfully obtained, or no longer necessary.
  • To obtain a copy of the information you gave us in a commonly used electronic format, and to have it transmitted onward where that is technically feasible.
  • To be indemnified for damages sustained through inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of your personal information.

Making a request or a complaint

Send requests to hello@rebicibusiness.com. We will acknowledge within 5 working days and respond substantively within 30 days. Where a request needs longer, we will tell you why and when to expect an answer.

If you are not satisfied with how we handled your request, you may complain to the National Privacy Commission, which supervises compliance with the Data Privacy Act. Their contact details are published at privacy.gov.ph, and complaints can be sent to complaints@privacy.gov.ph.

Children

Rebici is not for children under 13. We do not knowingly collect personal information from anyone under 13, and if we discover that we have, we will delete it.

If you are between 13 and 18, you may use Rebici only with the consent of a parent or guardian, who accepts our terms on your behalf and remains responsible for your use of the service.

A parent or guardian who believes a child has given us personal information without the consent they should have given can write to hello@rebicibusiness.com and we will remove it.

Security

Authorisation for every business action is enforced on our servers, not in the app. Enrollment and redemption tokens are short-lived and single-use. Authentication and sensitive transaction actions are rate-limited. Network traffic is encrypted in transit, and sensitive stored values — passwords, staff PINs and employee invite codes — are kept only as one-way hashes.

We keep audit logs of changes to permissions, employees, devices, programs and transactions, and require stronger confirmation for destructive or high-value actions.

No system is perfectly secure. You help by keeping your sign-in method and your staff PIN to yourself, and by removing employees and devices you no longer use.

If something goes wrong

If a security incident affects your personal information in a way that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the people affected within 72 hours of knowing about it, as the Data Privacy Act requires. We will tell you what happened, what information was involved, and what we are doing about it.

Changes to this policy

We may update this policy as the product changes. The current version is always published on this page, and the date at the top tells you when it last changed. Where a change materially affects how we handle your information, we will say so in the app rather than rely on you noticing it here.

Contact

Questions about this policy, or a request to access, correct or delete your data, can be sent to hello@rebicibusiness.com. Rebici is operated by Prometeuz.

See also our terms and conditions.