Skip to content
POSX
IndividualsBusinessNetworkDevelopersCompany
Contact
Legal Center

POSX Legal · United States

Privacy Policy

How POSX collects, uses, shares, protects and deletes personal information in the POSX app and on POSX websites.

Effective
October 1, 2026
Published
August 25, 2026
Version
1.0
Issued by
POSX US Inc.

On this page

  1. 1. About this policy and who is responsible for your information
  2. 1.1 Who we are
  3. 1.2 How to reach us about privacy
  4. 1.3 Scope
  5. 2. What the POSX app does, in privacy terms
  6. 3. Personal information we collect
  7. 3.1 Notes on particular categories
  8. 4. Where the information comes from
  9. 5. Automated decisions, profiling and artificial intelligence
  10. 5.1 Automated decisions we make
  11. 5.2 Artificial intelligence
  12. 6. When we share information, and with whom
  13. 6.2 We do not sell your personal information
  14. 7. Sending information across borders
  15. 8. How long we keep information
  16. 9. How we protect information
  17. 10. Your choices
  18. 10.1 Marketing
  19. 10.2 Device permissions and tracking
  20. 11. Closing your account and deleting your data
  21. 12. Blockchain records
  22. 13. Children
  23. 14. Your privacy rights
  24. 14.2 How to make a request
  25. 15. Other things you should know
  26. 15.1 Links and third-party services
  27. 15.2 App stores
  28. 15.3 Where we offer the app, and which POSX company you deal with
  29. 15.4 Changes to this policy
  30. 15.5 How to contact us
  31. Appendix A — Region-specific disclosures
  32. A.1 European Economic Area, United Kingdom and Switzerland
  33. A.2 California
  34. A.3 Other US states
  35. A.4 Hong Kong
  36. A.5 Markets where we do not offer the app
  37. Appendix B — Service providers and recipients
On this page

On this page

  1. 1. About this policy and who is responsible for your information
  2. 1.1 Who we are
  3. 1.2 How to reach us about privacy
  4. 1.3 Scope
  5. 2. What the POSX app does, in privacy terms
  6. 3. Personal information we collect
  7. 3.1 Notes on particular categories
  8. 4. Where the information comes from
  9. 5. Automated decisions, profiling and artificial intelligence
  10. 5.1 Automated decisions we make
  11. 5.2 Artificial intelligence
  12. 6. When we share information, and with whom
  13. 6.2 We do not sell your personal information
  14. 7. Sending information across borders
  15. 8. How long we keep information
  16. 9. How we protect information
  17. 10. Your choices
  18. 10.1 Marketing
  19. 10.2 Device permissions and tracking
  20. 11. Closing your account and deleting your data
  21. 12. Blockchain records
  22. 13. Children
  23. 14. Your privacy rights
  24. 14.2 How to make a request
  25. 15. Other things you should know
  26. 15.1 Links and third-party services
  27. 15.2 App stores
  28. 15.3 Where we offer the app, and which POSX company you deal with
  29. 15.4 Changes to this policy
  30. 15.5 How to contact us
  31. Appendix A — Region-specific disclosures
  32. A.1 European Economic Area, United Kingdom and Switzerland
  33. A.2 California
  34. A.3 Other US states
  35. A.4 Hong Kong
  36. A.5 Markets where we do not offer the app
  37. Appendix B — Service providers and recipients
Applies to

Users in the United States and in every market where POSX US Inc. is named as the app publisher

Governing law

Laws of the State of Delaware

Legal note

About this document

This document is part of the POSX legal pack published at https://posx.io/legal. It is written to be read by the people it applies to, not only by lawyers: where a term has a particular meaning, it is defined the first time it appears, and the sections that matter most to you are flagged as such. If anything here is unclear, write to legal@posx.io and we will explain it. Every previous version stays published, so you can always see what changed and when.

1. About this policy and who is responsible for your information

1.1 Who we are

1.1.1 POSX US Inc. ("POSX", "we", "us", "our") is the company responsible for the personal information described in this policy. Our registered office is 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. Incorporated in Delaware, United States. File / registration no. 10279819. EIN 39-3559683.

1.1.2 In data-protection terms we are the controller of that information: we decide what is collected and why. Where a partner merchant, a payment network or an app store separately decides how to use information about you, that party is a controller in its own right and its own privacy notice applies to what it does.

1.1.3 POSX is part of a group. POSX Commerce Technology Limited (Hong Kong), which operates the POSX network outside the United States, is an affiliate of ours. Where your account is served by that affiliate, its version of this policy applies instead; the two versions describe the same practices and differ only in the entity responsible and the local rights available to you. Both are published at https://posx.io/legal.

1.2 How to reach us about privacy

Reference table 1 in Privacy Policy
PurposeContact
Privacy enquiries and rights requestsprivacy@posx.io
Online rights request formhttps://posx.io/privacy/requests
Account deletionhttps://posx.io/account-deletion
Data protection officer / privacy leadour Privacy Lead, reachable at privacy@posx.io
EU representative (GDPR Art. 27)Not appointed. POSX does not offer the app in the European Economic Area — see section 15
UK representative (UK GDPR Art. 27)Not appointed. POSX does not offer the app in the United Kingdom — see section 15
Postal address16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States

1.3 Scope

1.3.1 This policy covers the POSX mobile application, the POSX websites at posx.io and their subdomains, and the customer support, email, SMS and push channels through which we communicate with you.

1.3.2 It does not cover: what a partner merchant does with information it collects from you in its own store, app or checkout; what Apple or Google collect through the app store or the operating system; or what a third-party wallet, exchange or blockchain network does with information you give it directly. Those parties publish their own notices.

2. What the POSX app does, in privacy terms

2.1 POSX is a cross-merchant rewards network. When you make a qualifying purchase at a partner merchant, POSX verifies that the purchase really happened and credits a reward to your POSX account. You can then redeem that reward at merchants in the network.

2.2 Three things follow from that model, and they explain most of what appears in this policy:

(a) We have to see purchases to reward them. POSX receives a record of qualifying transactions — merchant, amount, time, channel and a transaction fingerprint — either from the merchant, from a payment network you have permitted to share it, or from the payment method you have linked. We call this a Proof of Spend record.

(b) We keep the ledger of what you have earned. Your reward balance is a record on our own ledger — not a blockchain token, and not money we hold for you. Keeping that ledger accurate means we must be able to identify you reliably. Where the app also gives you a self-custodial wallet, the assets in it are yours and we cannot move them.

(c) We are required to verify who you are. Because we hold value for you and pay it out at merchants, we run identity verification and sanctions screening, and we keep those records for as long as the law requires — including after you close your account.

Legal note

Plain-language summary

We collect what we need to identify you, to prove your purchases, to pay and protect your rewards, and to keep the network free of fraud. We do not sell your personal information. You can see, correct, export and delete your data, and you can close your account from inside the app.

3. Personal information we collect

The table below is the complete list of what we collect, why, and — for users in the EEA and the UK — the legal basis we rely on. Categories marked optional are collected only if you choose to provide them or grant the relevant device permission.

Reference table 2 in Privacy Policy
CategoryWhat it includesWhy we collect itLegal basis (EEA / UK)
A. Account and profileName, email address, mobile number, password (stored only as a salted hash), country and language, referral code, profile photo (optional), account status and settings.Create and run your account; authenticate you; contact you about the service.Performance of our contract with you
B. Identity verification (KYC)Full legal name, date of birth, nationality, residential address, government identity document type, number, expiry and image; a selfie or short liveness video and the facial-geometry template our verification provider derives from it; proof of address; tax residency where required; sanctions, PEP and adverse-media screening results; the verification decision and its audit trail.Verify that you are who you say you are; meet anti-money-laundering and sanctions obligations; prevent impersonation and account takeover.Compliance with a legal obligation; Our legitimate interests (fraud prevention). Biometric data is processed only on your explicit consent — see the note on biometric data below
C. Purchases and Proof of SpendMerchant identity and location, purchase amount and currency, date and time, channel (in-store, online, card-linked), product category where the merchant provides it, a transaction fingerprint, the risk status of the transaction, and any refund, chargeback, reversal or adjustment.Determine whether a purchase qualifies; calculate and credit the reward; unwind rewards when a purchase is refunded or reversed; detect manipulation of the reward mechanism.Performance of our contract with you; Our legitimate interests (network integrity)
D. Payment methodA tokenised reference to a card you link, the last four digits, card brand, issuing bank and expiry; bank or payout details where you provide them. We do not store your full card number or security code.Match purchases to your account through the card networks; pay out where a payout method is used.Performance of our contract with you
E. Rewards and walletYour reward balance and full ledger of earn, redeem, adjustment and expiry entries; redemption history; tier or status level; referrals; promotions applied. Where the app provides a self-custodial wallet, the public address of that wallet and the transactions associated with it. Reward balances themselves are held on our own ledger and are not written to a blockchain.Run the reward programme; show you your balance and history; settle redemptions with merchants; produce statements and resolve disputes.Performance of our contract with you
F. Device and technicalDevice model, operating system and version, app version, time zone and language, IP address, mobile network, device identifiers (the per-installation vendor identifier on iOS and the app-set identifier on Android; not the advertising identifier), push notification token, crash reports, diagnostic and performance data.Deliver and secure the app; diagnose crashes and defects; detect fraudulent or automated access; measure reliability.Performance of our contract with you; Our legitimate interests (security, reliability)
G. LocationApproximate location inferred from your IP address; precise device location (optional, only with your operating-system permission); the location of merchants where you transact.Show nearby participating merchants and location-relevant offers; assess fraud risk; apply country restrictions.Your consent for precise location; Our legitimate interests for approximate location and fraud checks
H. App usageScreens viewed, features used, in-app searches, session length and frequency, offers shown and opened, notification interactions.Understand how the app is used, fix what does not work, and decide what to build next.Our legitimate interests (product improvement); Your consent where analytics uses non-essential SDKs
I. Support and communicationsMessages, chat and email correspondence with our support team, call notes, the contents of any dispute or complaint you raise, survey and feedback responses.Answer you; investigate and resolve disputes; train and quality-check our support team; keep a record of what was agreed.Performance of our contract with you; Our legitimate interests (service quality, defence of claims)
J. Marketing and consent recordsYour marketing preferences by channel, the date, time and wording of each consent or objection, and suppression records.Send only what you have agreed to receive, and prove that we honoured your choices.Your consent; Compliance with a legal obligation (record of consent)
K. Security and fraud signalsSign-in and authentication events, multi-factor status, device and session signals used to recognise your device, IP reputation, velocity and pattern signals, and security incident records.Keep your account and your reward balance secure; detect account takeover, collusion, split or circular transactions and reward farming.Our legitimate interests (security); Compliance with a legal obligation

3.1 Notes on particular categories

3.1.1 Sensitive information. Government identity numbers, precise location, and account credentials are treated as sensitive personal information under California law and as special category or restricted data under other laws. We use them only for the purposes in the table above, never for advertising, and never to infer characteristics about you.

3.1.2 Biometric data. Identity verification uses a facial-geometry template generated from your selfie and compared against your identity document. This is biometric data used to identify you uniquely. We ask for your explicit, separate consent before it is created, we tell you which provider performs the comparison, and the template is deleted once verification concludes and in any event within 30 days of the verification decision, and in no case later than three years after your last interaction with us. We obtain your written release before any template is created, and we never sell, lease, trade or otherwise profit from biometric information. If you do not want biometric verification, choose manual review in the verification screen or contact us, and we will review your documents manually instead — declining does not prevent you from opening an account. Texas CUBI, Colorado and other state biometric rules are applied on the same basis.

3.1.3 Card numbers. POSX does not receive, store or process full payment card numbers. Card linking is performed by our card-linking provider, named in the subprocessor list at posx.io/legal/subprocessors, which returns only a token and the display details listed in category D.

3.1.4 We do not collect your contacts, photo library, microphone, camera roll, health data, SMS content, call logs or a list of the other apps on your device. The camera is used only when you scan a code or capture an identity document, and images taken for that purpose are not retained beyond the purpose.

4. Where the information comes from

— From you — when you register, verify your identity, link a payment method, contact support, or set your preferences.

— From your device — automatically, when you use the app, as described in category F and in our Cookie and Tracking Policy.

— From partner merchants — the transaction records that make a purchase eligible for a reward.

— From payment networks and card-linked-offer providers — where you have authorised them to share qualifying transactions with us.

— From identity, sanctions and fraud providers — verification results, screening matches and risk signals.

— From app stores and attribution providers — install, campaign and, where you have consented, attribution data.

— From public blockchains — where the app provides a self-custodial wallet, the public record of that wallet's transactions. Reward balances are not on a blockchain.

— From someone who refers you — a referrer's code and, where they provide it, the contact detail they used to invite you.

5. Automated decisions, profiling and artificial intelligence

5.1 Automated decisions we make

We use automated systems in three places that can affect you:

Reference table 3 in Privacy Policy
DecisionWhat the system doesWhat happens if it goes against you
Reward eligibility and amountScores each Proof of Spend record against merchant, channel, activity, quality and risk coefficients to decide whether a purchase qualifies and what reward it earns.The reward is withheld, reduced or reversed. You can ask a person to review it.
Fraud and abuse controlsFlags patterns such as split or circular transactions, reward farming, collusion between accounts, and account-takeover signals.Rewards are held or reversed and, in serious cases, the account is suspended pending review.
Identity verificationCompares your identity document and selfie, and screens your details against sanctions, PEP and adverse-media lists.Verification fails and the account cannot be opened or continued. You can submit corrected documents and ask for manual review.

5.1.1 Because this processing is systematic, large-scale and includes biometric data, we carry out a data protection impact assessment before launch and before any material change to it, we maintain a record of processing activities, and we keep the outcome of the legitimate-interests balancing tests we rely on. A summary of the assessment is available to a supervisory authority on request.

5.1.2 Where a decision is made solely by automated means and has a legal or similarly significant effect on you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to us at privacy@posx.io and a person will review it.

5.1.3 California residents: from 1 January 2027, where we use automated decision-making technology to make a significant decision about you — including the provision or denial of a financial service — you may ask how it was used in your case and may opt out of that use, and we will offer an alternative process.

5.2 Artificial intelligence

5.2.1 We use machine-learning models for fraud detection, transaction classification and support triage. Where a third-party artificial-intelligence service processes personal information on our behalf, we name it in Appendix B, we bind it by contract to use the information only to provide the service to us, and we do not permit it to train its own general-purpose models on your information.

5.2.2 We do not sell or otherwise make your personal information available to a third party for the training of that party's own artificial-intelligence models. If that ever changes we will ask for your permission first.

6. When we share information, and with whom

6.1 We share personal information only in the situations listed below. Every service provider acts on our documented instructions under a written contract that requires at least the same protection this policy promises.

Reference table 4 in Privacy Policy
WhoWhat they receiveWhy
Partner merchantsConfirmation that a redemption is valid, the reward amount applied and a transaction reference. Your name is shared only where the merchant needs it to complete the transaction.So the merchant can honour your reward and reconcile settlement. Because a merchant decides for itself what to do with what it receives, this counts as sharing with a third party and is declared as such in our store disclosures. Merchants do not receive your identity documents, your full purchase history with other merchants, or your contact details for their own marketing unless you separately agree.
Identity verification and screening providersCategories B and A.To verify identity and screen against sanctions and PEP lists.
Wallet infrastructure provider (Privy)Your account identifier, authentication signals and wallet public address. Privy holds key material in a split form; POSX cannot move your assets and neither party holds a complete key on its own.To provision and operate your self-custodial wallet, and to let you authenticate and sign.
Treasury custody provider (Fireblocks)No user personal information. Fireblocks holds POSX's own treasury assets.To secure POSX's corporate assets. It has no access to your wallet or your data.
Cloud hosting, storage and network providersAll categories, as the infrastructure on which the service runs.To host and deliver the service.
Analytics, crash-reporting and attribution providersCategories F and H, and identifiers.To measure reliability and understand product usage. Non-essential SDKs run only with your consent where consent is required.
Communications providersContact details and message content.To send transactional email, SMS and push notifications, and marketing you have agreed to.
Customer support platformCategory I and enough account data to answer you.To run the support desk.
Payment, card-network and settlement partnersCategories C and D.To match purchases and settle redemptions.
Professional advisers, auditors and insurersWhatever is strictly necessary.To take legal, tax and accounting advice, to be audited, and to obtain insurance.
Regulators, law enforcement and courtsWhatever the law requires.To comply with a valid legal obligation, court order or lawful request, and to establish or defend legal claims. We review each request, and we refuse or narrow requests that are overbroad or unlawful.
Our affiliatesAccount, transaction and security data as needed.So that POSX Commerce Technology Limited (Hong Kong) and POSX can run one network across markets.
An acquirer, investor or successorData relevant to the transaction, under confidentiality.In connection with a financing, merger, acquisition, reorganisation or sale of assets. If control of your information changes, we will tell you before it becomes subject to a different policy.

6.2 We do not sell your personal information

6.2.1 We do not sell personal information, and we have not sold personal information in the twelve months before the date of this policy. We do not share personal information for cross-context behavioural advertising as those terms are defined under California law, and we do not process the personal information of anyone we know to be under 16 for those purposes.

7. Sending information across borders

7.1 POSX is based in the United States and uses service providers in the United States and elsewhere. If you are in the European Economic Area, the United Kingdom or Switzerland, your information will be transferred outside your home country.

7.2 For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum for UK transfers, supported by a transfer impact assessment and, where the assessment requires it, additional technical measures such as encryption in transit and at rest.

7.3 A list of the countries in which our main providers process personal information is in Appendix B. You can ask us for a copy of the transfer safeguards we rely on by writing to privacy@posx.io.

8. How long we keep information

We keep personal information only as long as we need it for the purpose we collected it for, plus any period the law requires. The table sets our standard periods.

Reference table 5 in Privacy Policy
WhatHow longWhy that long
Account and profileLife of the account, then 12 monthsTo let you reopen an account and to resolve late disputes.
Identity verification records and screening results5 years after the account closes, or longer where a specific law or an open investigation requires itAnti-money-laundering record-keeping standards. Retained even if you delete your account.
Biometric templates30 days after verification concludes — deleted once verification concludesOnly needed for the verification decision itself.
Transaction, Proof of Spend and reward ledger records7 years from the end of the financial year in which the transaction occurredAccounting, tax and audit requirements, and dispute resolution.
Support correspondence24 months from closure of the matterTo handle follow-ups and repeat issues.
Marketing consents, objections and suppression listsIndefinitely, in a minimal formWe must keep a record of your opt-out in order to honour it.
Device, analytics and usage dataUp to 26 months, then aggregated or deletedLong enough to see year-on-year patterns, no longer.
Security, access and fraud logs12 to 24 months, longer for an active investigationTo investigate incidents and account takeovers.
BackupsRolling 35 daysDeleted records disappear from backups as the cycle rotates.
Records written to a public blockchainPermanent — outside our controlSee section 12.

9. How we protect information

9.1 We maintain a written information security programme with administrative, technical and physical safeguards proportionate to the sensitivity of what we hold. Personal information is encrypted in transit and at rest, access is restricted on a least-privilege basis and requires multi-factor authentication, and privileged access to production systems is logged and reviewed. Our Security Policy, published at https://posx.io/legal, describes the programme, our incident-response commitments and how to report a vulnerability.

9.2 No system is perfectly secure. If a breach affecting your personal information occurs and the law requires us to tell you, or where there is a real risk of harm to you, we will notify you without undue delay. Where the GDPR or UK GDPR applies we notify the supervisory authority within 72 hours of becoming aware of the breach, and we notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

10. Your choices

10.1 Marketing

10.1.1 You can turn marketing email, SMS and push notifications on or off at any time in Settings → Notifications, by using the unsubscribe link in any marketing email, or by writing to privacy@posx.io. We act on an opt-out promptly and in any event within 10 business days, free of charge.

10.1.2 Service messages — verification codes, security alerts, changes to these documents, receipts and balance notices — are part of the service and are not marketing. You cannot opt out of them while your account is open.

10.2 Device permissions and tracking

— Location — grant or withdraw at any time in your device settings. The app works without it; you will simply not see nearby-merchant features.

— Notifications — grant or withdraw in your device settings.

— Camera — used only when you scan a code or capture an identity document.

— Tracking (iOS) — POSX does not track you across apps and websites owned by other companies, so the app does not show Apple's App Tracking Transparency prompt. If that ever changes we will ask for your permission through that prompt first, and declining will not change anything about the app or your rewards.

— Advertising identifier (Android) — POSX does not use it for advertising. You can reset or delete it in your device settings at any time.

10.2.1 We honour the Global Privacy Control and other recognised opt-out preference signals sent by your browser or device as a valid opt-out of sale and of sharing for targeted advertising, wherever the law gives that signal effect.

11. Closing your account and deleting your data

11.1 You can delete your POSX account from inside the app at Settings → Account → Delete account. You can also request deletion, without reinstalling the app, at https://posx.io/account-deletion.

11.2 Before you delete, please read this: any unredeemed reward balance is forfeited when your account closes. Rewards have no cash value and cannot be paid out. Redeem what you want to keep first.

What we delete

— Your profile, contact details and credentials.

— Your device, usage and analytics records associated with your account.

— Your marketing preferences, other than the minimum needed to keep honouring your opt-out.

— Your support correspondence, once any open matter is closed.

— Your identity documents and biometric templates, once the retention period in section 8 expires.

What we keep, and why

— Identity verification and screening records, for the anti-money-laundering period in section 8.

— Transaction and reward ledger records, for the accounting and tax period in section 8.

— Records needed to establish, exercise or defend a legal claim, or to comply with a court order, a regulator's direction or a legal hold.

— A minimal suppression record so that we do not contact you again.

— Anything already written to a public blockchain, which we cannot alter or erase.

11.3 Deletion takes effect on our live systems within 30 days of your request, and backups containing the deleted records are overwritten within the backup cycle stated in section 8. We will confirm when it is done.

12. Blockchain records

12.1 Your rewards are not on a blockchain. Reward balances, the earn and redeem ledger and Proof of Spend records are held on POSX's own systems. Nothing about your rewards is written to a public chain.

12.2 Where the app provides a self-custodial wallet, that wallet is a blockchain address, and anything you do with it is public and permanent. Information on a public blockchain is replicated across many computers, can be read by anyone, and cannot be changed or deleted by POSX, by Privy or by anyone else. Blockchain addresses are pseudonymous rather than anonymous: if an address can be connected to you, so can the whole history of that address.

12.3 We do not write your name, contact details, identity documents or any special category data on-chain. Where you exercise a right of erasure we delete the off-chain information that links you to an address; the on-chain record itself will remain, because no one is able to remove it.

13. Children

13.1 POSX is a financial service for adults. The app is not directed to children, and you must be at least 18 years old (or the age of majority where you live, if higher) to hold an account. We do not knowingly collect personal information from children.

13.2 If we learn that we hold information about a child, we will close the account and delete the information promptly, except where a law requires us to keep a record. If you believe a child has given us information, write to privacy@posx.io.

14. Your privacy rights

14.1 Depending on where you live, you have some or all of the rights below. We do not charge for exercising them and we will not treat you differently for doing so.

— Access — get a copy of the personal information we hold about you, and information about how we use it.

— Correct — have inaccurate information corrected.

— Delete — have your information deleted, subject to the exceptions in section 11.

— Portability — receive the information you gave us in a structured, machine-readable format, or have it sent to another provider where technically feasible.

— Object and restrict — object to processing based on our legitimate interests, and ask us to restrict processing while a dispute is resolved.

— Withdraw consent — at any time, without affecting what we did before you withdrew it.

— Opt out — of sale, of sharing for targeted advertising, and of profiling that produces legal or similarly significant effects.

— Limit — restrict our use of sensitive personal information to what is necessary to provide the service.

— Human review — of a solely automated decision that significantly affects you.

— Complain — to your data protection authority.

14.2 How to make a request

14.2.1 Use the form at https://posx.io/privacy/requests, or write to privacy@posx.io. We will verify your identity before we act — usually by asking you to make the request from inside your account or from the email address on file. An authorised agent may make a request for you if they provide written proof of authority.

14.2.2 We answer within the period the law allows: one month under the GDPR and UK GDPR (extendable by two further months for complex requests), 45 days under most US state laws (extendable once by a further 45 days), and 40 days under the Personal Data (Privacy) Ordinance. If we refuse a request we will tell you why and how to challenge it.

14.2.3 You always have the right to complain to the attorney general of your state and, if you are a California resident, the California Privacy Protection Agency, or to the supervisory authority in your country. We would rather you came to us first so we can put it right.

14.2.4 Region-specific rights, and the disclosures each region requires, are set out in Appendix A.

15. Other things you should know

15.1 Links and third-party services

15.1.1 The app and our sites link to merchant sites, payment providers and other third parties. We do not control them and we are not responsible for their privacy practices. Read their notices before you give them information.

15.2 App stores

15.2.1 Apple and Google collect information about your download and use of the app under their own policies. What we declare to them about our data practices is set out in our App Store privacy details and our Google Play Data safety section, both of which are consistent with this policy.

15.3 Where we offer the app, and which POSX company you deal with

15.3.1 The app is offered in the United States and in Hong Kong. If you registered with a United States address, your account is with POSX US Inc and this policy applies to you in the version published for that company. If you registered anywhere else, your account is with POSX Commerce Technology Limited. Both versions are published side by side at https://posx.io/legal, and your account settings show which one applies to you.

15.4 Changes to this policy

15.4.1 We will update this policy when our practices change. The version number and effective date at the front of the document always tell you which version you are reading, and we keep the previous versions available at https://posx.io/legal. If a change materially affects your rights, we will tell you in the app or by email at least 30 days before it takes effect.

15.5 How to contact us

15.5.1 Write to privacy@posx.io, or by post to POSX US Inc., 16192 Coastal Highway, Lewes, Delaware 19958, United States (registered office); correspondence to 340 Madison Avenue, Suite 6D, New York, NY 10173, United States. If you are not satisfied with our answer, you may escalate to the POSX Legal team, legal@posx.io, marked "Escalation" and then to your data protection authority.

Appendix A — Region-specific disclosures

A.1 European Economic Area, United Kingdom and Switzerland

A.1.1 The controller is POSX US Inc.. Our representative under Article 27 is named in section 1.2. The legal bases we rely on are in the table in section 3; where we rely on legitimate interests, those interests are securing the network, preventing fraud, improving the product and defending legal claims, and we have carried out a balancing assessment which we will share on request.

A.1.2 You have the rights listed in section 14 and the right to lodge a complaint with your local supervisory authority. Providing identity verification data is a requirement of entering into the contract with us; if you do not provide it we cannot open or continue your account.

A.2 California

A.2.1 This section is our notice at collection and our privacy policy for the purposes of the California Consumer Privacy Act as amended.

Reference table 6 in Privacy Policy
CCPA category of personal informationCollected?PurposeDisclosed to
Identifiers (name, email, phone, IP, device and account identifiers)YesAccount, service, security, communicationsService providers, merchants (limited), authorities
Customer records (Cal. Civ. Code §1798.80) including financial detailsYesAccount, rewards, payoutsService providers, payment partners
Commercial information (purchases, redemptions, reward history)YesReward calculation, service, fraudService providers, merchants (limited)
Biometric information (facial-geometry template for verification)Yes, with consentIdentity verificationVerification provider only
Internet or network activity (app usage, diagnostics)YesReliability, product improvementAnalytics providers
Geolocation dataYesNearby merchants, fraud, country restrictionsService providers
Audio, visual or similar (identity document images, support recordings)YesVerification, support qualityVerification and support providers
Professional, employment or education informationNo——
Sensitive personal information (government ID number, account credentials, precise geolocation, biometric data)YesOnly to verify identity, secure the account and provide the serviceVerification and security providers
Inferences drawn to create a profileLimited — risk and eligibility scoring onlyFraud prevention and reward eligibilityNot disclosed for advertising

A.2.2 We do not sell or share personal information as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes beyond those permitted by section 1798.121, so the right to limit does not restrict anything we do — you may still ask us to limit and we will confirm.

A.2.3 California residents have the rights in section 14, including the right to know, delete, correct, opt out and to be free from discrimination. Requests are answered within 45 days, extendable once. You may use an authorised agent. Contact us as set out in section 14.2.

A.3 Other US states

A.3.1 If you live in a state with a comprehensive privacy law — including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah or Virginia, and further states as their laws take effect — you have the rights in section 14 as your state grants them. Most of those states also give you the right to appeal a refusal: write to privacy@posx.io with "privacy appeal" in the subject line and we will respond within 45 days and tell you how to contact your attorney general if you remain dissatisfied.

A.4 Hong Kong

A.4.1 This section, together with the collection notice shown when you register, is our Personal Information Collection Statement under Data Protection Principle 1(3) of the Personal Data (Privacy) Ordinance (Cap. 486).

— Providing the data in categories A to D is obligatory — we cannot open or run your account without it. Providing the data in categories G and J is voluntary.

— The purposes of collection are those in section 3, and the classes of transferee are those in section 6.

— You may request access to and correction of your personal data under sections 18 and 22 of the Ordinance. We respond within 40 days. We may charge a fee for complying with a data access request, which will not be excessive and will be limited to the direct costs of compliance.

— You may at any time, free of charge, require us to stop using your personal data in direct marketing.

— Requests should be sent to privacy@posx.io or by post to the address in section 1.1, marked for the attention of the Data Protection Officer.

A.5 Markets where we do not offer the app

A.5.1 POSX offers the app in the United States and in Hong Kong. We do not offer it, market it or accept registrations in the European Economic Area, the United Kingdom or Switzerland, and we have not appointed a representative under Article 27 of the GDPR because we do not target those markets.

A.5.2 We nonetheless hold ourselves to the standard the GDPR sets, because it is the right standard and because people travel. If you are in a country where we do not offer the app and you have contacted us anyway, the rights in section 14 are available to you on the same terms as to everyone else.

A.5.3 When we open a new market we will add the disclosures and the local complaint routes that market requires — Canada, Brazil and Australia each have their own — before the app becomes available there, and we will publish the updated policy first.

Appendix B — Service providers and recipients

The table below sets out what is processed on our behalf and by which kind of provider. The current name and processing location of each provider is published, and kept up to date, at posx.io/legal/subprocessors. We keep the list there rather than in this policy so that changing a supplier does not mean redrafting a document you have already read — the list is part of this policy and carries the same commitments.

We will tell you at least 30 days before adding a provider that materially changes where or how your information is processed, and you can subscribe to changes to that page.

Reference table 7 in Privacy Policy
FunctionWhat it processesNamed at posx.io/legal/subprocessors
Cloud hosting and storageAll categoriesYes
Identity verification and liveness detectionCategory BYes
Sanctions, PEP and adverse-media screeningCategory BYes
Wallet infrastructure — self-custodialCategories A, E, KPrivy. Privy provisions your wallet and holds key material in a split form. Neither Privy nor POSX holds a complete key, and POSX cannot move your assets.
Treasury custody — POSX's own assetsNo user personal informationFireblocks. Fireblocks holds POSX's corporate assets. It has no access to your wallet and no access to your personal information.
Card linking and payment tokenisationCategories C and DYes
Analytics and product measurementCategories F and HYes
Crash and performance reportingCategory FYes
Attribution and install measurementCategory FNone at present. We do not run install attribution.
Email, SMS and push deliveryCategories A and JYes
Customer support platformCategories A and IYes
Fraud and risk scoringCategories C, F and KYes
Artificial-intelligence services used in the productSee the subprocessor listNamed there if any is used, together with a written commitment that it may not train its own models on your information.

B.1 Every provider on that list is bound by a written data processing agreement covering purpose limitation, confidentiality, security, sub-processing, breach notification to us without undue delay, audit rights, international transfer safeguards and deletion on termination. Transfers out of the EEA or the UK rely on the European Commission's Standard Contractual Clauses and the UK Addendum, as described in section 7.

Questions about this document

Contact POSX Legal

We can explain how this document applies to the POSX service.

legal@posx.io

POSX Legal

Related policies

ConsumerTerms of ServiceSecuritySecurity PolicyConsumerCookie and Tracking PolicySoftware LicenceEnd User License AgreementAccessibilityAccessibility Statement
POSX

Rewards for real-world spending.

Official channels

Stay in the loop

Get the latest updates on product news, rewards and announcements.

Product

IndividualsBusinessNetworkDevelopers
Product
IndividualsBusinessNetworkDevelopers

Company

About POSXNewsroomContactTrust
Company
About POSXNewsroomContactTrust

Resources

Developer docsBrand center
Resources
Developer docsBrand center

Legal

Privacy PolicyTerms of ServiceCookie PolicySecurityAccessibilityDelete your account
Legal
Privacy PolicyTerms of ServiceCookie PolicySecurityAccessibilityDelete your account

Legal notice

POSX is a rewards network, not a bank. POSX Rewards are a promotional benefit funded by participating merchants. They have no cash value, cannot be exchanged for cash, transferred or traded, and are not a deposit, e-money, a security or an investment. Reward balances are records on POSX's own systems and are not held on any blockchain. They are not insured by the Federal Deposit Insurance Corporation or protected by any deposit protection scheme.

Where the POSX app provides a wallet, it is self-custodial and provisioned through Privy: the assets in it belong to you and POSX cannot move, freeze or recover them. POSX does not take custody of user funds or assets.

Nothing on this site is financial, investment, legal or tax advice, or an offer to buy or sell any security. Any statement about future performance, adoption or value is a forward-looking statement and should not be relied on.

Services in the United States are provided by POSX US Inc., 340 Madison Ave, Suite 6D, New York. Services elsewhere are provided by POSX Commerce Technology Limited, Unit J&K, 34/F, Office Tower, Convention Plaza, No. 1 Harbour Road, Wan Chai, Hong Kong (Certificate of Incorporation No. (UBI) 80761816). Availability varies by country and not all features are available in all markets.

© 2026 POSX. All rights reserved.