> ## Documentation Index
> Fetch the complete documentation index at: https://docs.brand-wallet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# BrandWallet Legal: Privacy, GDPR, CCPA, and PIPEDA FAQ

> BrandWallet's compliance with GDPR, CCPA, and PIPEDA — data protection measures, customer data rights, privacy policy, and terms of service summary.

BrandWallet is built on a foundation of trust. Operating a loyalty program means handling customer data responsibly, and we take that obligation seriously. This page outlines how BrandWallet protects your customers' data, which privacy regulations we comply with, what data we collect and why, and what your customers are entitled to under applicable law. If you have compliance questions beyond what's covered here, our legal team is available to help.

<AccordionGroup>
  ## Privacy Regulations and Compliance

  <Accordion title="Which privacy regulations does BrandWallet comply with?">
    BrandWallet complies with all major international privacy regulations, including:

    | Regulation            | Jurisdiction        | What it covers                                                                                          |
    | --------------------- | ------------------- | ------------------------------------------------------------------------------------------------------- |
    | **GDPR**              | European Union      | General Data Protection Regulation — strict rules on data collection, processing, and individual rights |
    | **CCPA**              | California, USA     | California Consumer Privacy Act — rights for California residents over their personal data              |
    | **PIPEDA**            | Canada              | Personal Information Protection and Electronic Documents Act — rules on private-sector data handling    |
    | **Local regulations** | Other jurisdictions | Compliance with regional privacy and data protection laws where applicable                              |

    **How we maintain compliance:**

    * Data protection by design — privacy is built into the platform from the ground up
    * Regular privacy impact assessments
    * Ongoing compliance audits
    * Transparent data practices and clear user consent management

    <Note>
      BrandWallet operates globally. If your business operates in a jurisdiction not listed above, contact our support team to discuss your specific compliance requirements.
    </Note>
  </Accordion>

  ## Data Protection Measures

  <Accordion title="What security measures protect customer data?">
    BrandWallet implements industry-standard security measures across every layer of the platform:

    * **Encryption** — all data is encrypted in transit (TLS) and at rest, so it's never exposed in readable form
    * **Access controls** — role-based permissions combined with multi-factor authentication ensure that only authorized users can access sensitive data
    * **Regular security audits** — the platform undergoes regular security assessments and penetration testing to identify and address vulnerabilities
    * **Incident response** — a comprehensive breach response procedure is in place to detect, contain, and report any security incidents in accordance with regulatory requirements
    * **Staff training** — all BrandWallet employees receive regular privacy and security training

    <Warning>
      You are responsible for managing access permissions within your own BrandWallet account. Ensure that you only grant dashboard access to team members who need it, and revoke access promptly when someone leaves your organization.
    </Warning>
  </Accordion>

  ## Customer Data Rights

  <Accordion title="What rights do my customers have over their data?">
    Under GDPR, CCPA, PIPEDA, and similar regulations, your customers have the following rights regarding their personal data:

    | Right                    | What it means                                                                  |
    | ------------------------ | ------------------------------------------------------------------------------ |
    | **Access**               | Customers can request to see what personal data you hold about them            |
    | **Correction**           | Customers can ask you to correct inaccurate or incomplete information          |
    | **Deletion**             | Customers can request that their data be deleted (the "right to be forgotten") |
    | **Portability**          | Customers can request their data in a portable, machine-readable format        |
    | **Object to processing** | Customers can object to certain uses of their data                             |
    | **Withdraw consent**     | Customers can withdraw their consent to data processing at any time            |

    **BrandWallet provides tools to help you:**

    * Manage and respond to incoming customer data requests
    * Export individual customer records
    * Delete customer data upon request
    * Update privacy preferences and consent settings

    <Note>
      When a customer exercises one of these rights, you are responsible for responding within the timeframes required by applicable law (e.g., 30 days under GDPR). BrandWallet's tools are designed to help you fulfill these requests efficiently.
    </Note>
  </Accordion>

  ## Privacy Policy Summary

  <Accordion title="What data does BrandWallet collect — and what does it not collect?">
    **Data we collect (only what is necessary):**

    * Customer information required to operate your loyalty program (e.g., name, email address, phone number)
    * Transaction data for program management and reporting
    * Usage analytics to improve platform functionality
    * Contact information for customer support purposes

    **Data we do NOT collect:**

    * Personal information that isn't necessary for the service
    * Sensitive financial data beyond what's required to process loyalty transactions
    * Data intended for third-party marketing purposes
    * Any information collected without explicit customer consent

    <Tip>
      You can review BrandWallet's full Privacy Policy and Data Processing Agreement in your account dashboard under the Legal & Compliance section.
    </Tip>
  </Accordion>

  <Accordion title="What is customer data used for — and what is it not used for?">
    **We use your data only to:**

    * Provide and operate the BrandWallet loyalty platform
    * Improve platform features and reliability over time
    * Offer customer support and technical assistance
    * Comply with our own legal obligations

    **We do NOT:**

    * Sell customer data to any third party, ever
    * Use your data for marketing unrelated to your BrandWallet account
    * Share your data with other businesses without your explicit consent
    * Retain data beyond the period necessary for the stated purposes

    <Warning>
      BrandWallet will never contact your customers directly for marketing purposes using data collected through your loyalty program.
    </Warning>
  </Accordion>

  ## Terms of Service Highlights

  <Accordion title="What are the key points of BrandWallet's Terms of Service?">
    By using BrandWallet, you agree to the following core terms:

    **Your responsibilities as a merchant:**

    * Use the platform in compliance with all applicable laws and regulations
    * Respect your customers' privacy rights and handle their data appropriately
    * Maintain accurate account information
    * Not misuse the platform, its features, or the data accessible through it

    **Service availability:**

    * BrandWallet targets **99.9% platform uptime** — your loyalty program should be accessible to customers at virtually all times
    * Scheduled maintenance is communicated in advance with as much notice as possible
    * Regular platform updates and security patches are deployed to keep the service secure and current

    **Support:**

    * Customer support is available during business hours, with extended support for higher-tier plans
    * See the [Support page](/faq/support) for full details on response times and contact channels

    <Note>
      The full Terms of Service, Privacy Policy, Data Processing Agreement, and Cookie Policy are available in your account dashboard. We recommend reviewing these documents when you first set up your account.
    </Note>
  </Accordion>
</AccordionGroup>
