Legal

Privacy Policy

How Kardy handles your account, memberships and loyalty activity—and the choices you have.

Last updated 8 September 2026 · Singapore

Who this policy covers

Kardy is a Singapore-based loyalty platform for customers and the businesses they visit. This policy covers Kardy’s website, browser wallet and merchant application. References to Kardy, we and us mean the operator of the Kardy service.

Kardy manages account identity and the platform. Participating merchants manage their own loyalty programmes and use membership information for those programmes. Depending on the activity, Kardy processes information for its own service purposes or on a merchant’s instructions. A merchant’s separate privacy notice applies to its own use of your information; joining one organisation does not give every merchant access to your memberships.

Information we handle

Account information: your sign-in email, profile name, optional phone number, avatar and account identifiers. Authentication is handled by InsForge Auth. If you use an external sign-in provider, we receive the account information it shares for authentication. Do not send passwords through support or include them in your profile.

Membership and activity: the organisations you join, membership identifiers, stamp balances, assigned rewards, redemption records, dates and outlets associated with visits, and signup attribution where available. Your QR uses an opaque identifier rather than displaying your email or phone number, but it still links to your account and should be treated as private.

Merchant information: organisation and outlet details, branding and uploaded assets, programme settings, authorised team members, roles, invitations, ownership-transfer records and related verification activity. Public listings display the business information selected for publication.

Referrals and communications: referral links, the relationship between an inviter and a joining member, qualification and bonus activity, marketing consent and withdrawal records, broadcast content and delivery status where enabled. We also handle information you provide when requesting help.

Billing and technical information: merchant customer and subscription identifiers, plan and payment status, plus request, device, browser and diagnostic information needed to operate and secure the service. Payment details submitted at checkout are handled by the payment provider, not stored as card numbers in Kardy’s application database.

Why we use information

We use information to authenticate accounts, display memberships, record stamps and claims, apply outlet and referral rules, manage organisation access, process merchant subscriptions, respond to requests, and prevent fraud and unauthorised access. We also use necessary diagnostic information to investigate failures and maintain the service.

We collect, use and disclose personal data for purposes notified to you, with consent where required or another basis permitted by applicable law. Providing account and membership information is necessary for those features to work. Optional marketing consent is separate from joining a programme.

Who receives information

Authorised people at a merchant can access the customer and programme information needed for their permitted duties. Organisation owners administer team access. A role at one organisation does not grant access to another organisation’s data. Referral interfaces show relevant invitation progress, not a friend’s email or phone number.

InsForge provides authentication, database and related backend services. Polar handles merchant subscription checkout and billing. Infrastructure, storage and email providers process information necessary to deliver their enabled services.

If native Apple Wallet or Google Wallet delivery is available and you choose it, the relevant provider receives pass information required to issue or display that pass. These optional integrations may not be available in every environment. Links to external websites are subject to those providers’ own policies.

Information may be disclosed when legally required, to investigate abuse or protect rights and safety, or as part of a business restructuring subject to applicable privacy obligations. Kardy does not sell personal data.

Marketing choices

Where merchant email broadcasts are enabled, promotional delivery requires the applicable programme’s marketing consent. You can withdraw through the unsubscribe route provided with the message or available programme controls. Withdrawing marketing consent does not remove your membership or existing stamps.

Security, verification, subscription and other necessary service messages are distinct from optional promotions. Delivery features depend on the service configuration; a saved draft does not mean an email has been sent.

Cookies, storage and device permissions

Kardy uses authentication cookies or tokens and browser storage to maintain sessions and preferences such as your theme. Browser-wallet functionality may cache application resources on your device. Signing out and clearing site data can remove local information but do not themselves delete server-side membership records.

Scanning may request camera permission. You can deny or revoke it in your browser and use an available manual-code option instead. Outlet attribution records the outlet associated with an action; it is not a promise that Kardy continuously tracks your device location.

We use Google Analytics to understand visits to our public website and merchant workspace and improve the service. Analytics is enabled by default and uses cookies to collect usage and device information. Analytics is not enabled on sign-in or member-wallet pages. We do not intentionally send account details, QR tokens, or URL query strings to Google Analytics, and advertising features are disabled.

Retention and security

Account and programme data are kept for as long as needed for the purposes described here, including operating memberships, resolving disputes and meeting legal obligations. When retention is no longer necessary for a legal or business purpose, information should be deleted or anonymised. Specific retention periods and backup deletion schedules must be confirmed before launch; this policy does not promise immediate erasure from every system.

Deleting a reward changes its availability and affected card progress; it does not erase past redemption audit history. Unsubscribing from marketing is not an account-deletion request. Information needed to honour an unsubscribe choice may be retained for that purpose.

Kardy uses authenticated access, organisation-scoped permissions and server-side checks to protect programme data. No online service is completely secure. If a breach occurs, Kardy will assess it and provide notifications required by applicable law.

Processing outside Singapore

Service providers may process information outside Singapore. Such transfers must meet applicable PDPA requirements, including comparable protection where required. Provider locations and transfer safeguards must be verified for the deployed service; using Kardy alone is not a waiver of those protections.

Your requests and choices

Subject to applicable exceptions, you can request access to personal data Kardy holds about you, information about its use or disclosure during the preceding year, and correction of inaccurate information. You may also withdraw consent on reasonable notice. We may need to verify your identity and explain any consequences for features that depend on that information.

You can update supported profile fields in account settings. For other access, correction, withdrawal or deletion requests, a working public data-protection contact route must be designated before this policy takes effect. The current Contact page is a general contact route, not yet a confirmed privacy-request service. Do not send passwords, full payment details or unnecessary identity documents.

For information independently controlled by a participating merchant, you may also need to contact that merchant. Requests will be addressed within applicable legal requirements; if access cannot be provided within 30 days, we will explain when a response can be expected. You may raise unresolved data-protection concerns with Singapore’s Personal Data Protection Commission.

Young users

Merchants should not use Kardy to collect children’s information without the notices, safeguards and consent required by law. If you are not legally able to agree to the service terms, involve a parent or guardian. An explicit age policy and any necessary parental-consent process must be settled before offering Kardy directly to children.

Changes to this policy

We will update the revision date when this policy changes. Material changes will be communicated appropriately, and additional consent will be sought where required before using information for a new purpose. A policy update does not remove rights provided by law.

Questions? Contact Kardy. Read our Terms & Conditions.