Legal

Privacy Policy

Effective date: May 14, 2026 · Version 2026-05-14

Important — not legal advice. This document is a starting template for compliance with U.S. and international privacy laws including CCPA/CPRA, VCDPA, and GDPR. You must have a licensed privacy attorney in your jurisdiction review and customize this policy before publishing it to real users. Privacy law obligations vary by state, country, and industry, and change frequently.

1. Who we are

QEZLIO operates a multi-merchant loyalty network. Customers earn and redeem rewards across participating businesses ("Merchants") in our network.

2. Information we collect

  • Account info you provide (name, email, phone, ZIP).
  • Transaction events from Merchants (amount, location, timestamp, points earned/redeemed).
  • Device and usage data (IP address, app interactions).

3. Cross-merchant data sharing — your opt-in is required

The QEZLIO network passes a limited transaction record between participating Merchants so points earned at one store can be redeemed at another. Under the CCPA/CPRA, VCDPA, and GDPR, this requires your explicit opt-in. You may withdraw consent at any time from your account settings; doing so will disable cross-merchant redemption but will not affect points already earned.

4. Data minimization

Merchants never receive your name, email address, phone number, or payment card details from us. Transactions are identified to Merchants only by a rotating opaque identifier that cannot be reversed to identify you.

5. Financial incentive disclosure (CCPA §1798.125)

QEZLIO offers a financial incentive (loyalty benefits) in exchange for your participation. The monetary value of personal information used to operate the program, and the specific terms of any incentive, will be disclosed in the pilot program terms provided to participants. You may withdraw from the program at any time.

6. Your privacy rights

  • Right to know what personal information we hold about you.
  • Right to correct inaccurate personal information.
  • Right to delete your personal information (see Section 7).
  • Right to opt out of the sale or sharing of personal information for cross-context behavioral advertising. We do not sell personal information.
  • Right to non-discrimination for exercising these rights.

7. Right to delete

When you submit a deletion request, we will honor it across our network within the time required by applicable law (45 days under CCPA / 30 days under GDPR) and notify you when deletion is complete. To submit a request, contact us at the address in Section 10.

8. Data retention

We retain account data for the life of your account and retain transaction records only as long as required by applicable financial recordkeeping law, after which they are deleted. Aggregated, de-identified analytics may be retained indefinitely.

9. International transfers

If you access the service from outside the United States, your information will be transferred to and processed in the United States. We rely on Standard Contractual Clauses where required for transfers from the EEA, UK, or Switzerland.

10. Contact

Privacy questions: privacy@universalrewards.example. California residents may also designate an authorized agent to submit requests on their behalf.

See also: Terms of Service.