Legal
Privacy Policy
Effective date: 1 September 2026. Version 1.0
Chhaap respects your privacy and aims to collect only the information reasonably necessary to provide and protect our services.
This Privacy Policy explains how Chhaap collects, holds, uses and discloses personal information when people use chhaap.app and Chhaap-powered services.
1. Who this policy applies to
This policy may apply to:
- business owners using Chhaap;
- staff members authorised by a business;
- people joining a Chhaap-powered loyalty program;
- people using a Chhaap digital loyalty card;
- people using QR or NFC experiences;
- people adding a Chhaap-powered pass to a digital Wallet;
- people visiting a Chhaap-hosted website;
- people submitting an enquiry or support request; and
- other users of Chhaap services.
A participating business may also have its own privacy policy describing how that business uses customer information.
2. Chhaap and participating businesses
A participating business generally determines the purpose of its loyalty program, what customer information it chooses to collect through available Chhaap features and how it communicates with its customers.
Chhaap provides the technology used to operate that program and may handle relevant information on the business's behalf.
Chhaap also handles some information for its own legitimate operational purposes, including account administration, security, fraud prevention, billing, customer support and improving the Chhaap service.
3. Information we may collect
The information we collect depends on which Chhaap features you use.
Business and staff information
We may collect:
- name;
- email address;
- telephone number;
- business name;
- business contact information;
- role or permission level;
- authentication information;
- account settings;
- organisation membership; and
- communications with Chhaap.
Business content
A Business Customer may provide:
- business logos;
- colours and branding;
- business descriptions;
- addresses;
- opening hours;
- website content;
- photographs;
- loyalty program settings;
- reward descriptions;
- review links; and
- other information required to configure its Chhaap experience.
Loyalty customer information
Depending on how a participating business configures Chhaap, we may process:
- name or display name;
- email address;
- mobile number;
- loyalty membership identifier;
- participating business;
- visits or stamps;
- rewards earned or redeemed;
- transaction dates and times;
- loyalty status;
- card configuration; and
- other information voluntarily provided as part of the program.
Not every loyalty program requires all of this information.
Where possible, Chhaap uses technical identifiers rather than embedding personal information directly in QR or NFC credentials.
QR, NFC and Wallet information
When QR, NFC or Wallet features are used, we may process technical information required to:
- identify the relevant loyalty card or destination;
- validate authorised activity;
- issue or update a digital pass;
- protect against misuse; and
- troubleshoot the service.
Digital Wallet providers may separately collect information under their own privacy policies.
Review interactions
When you use a Chhaap review link, QR code or NFC Review Point, we may record limited technical information about the interaction for functionality, security or aggregate reporting.
A review submitted directly to Google or another third-party platform is submitted to that platform.
Chhaap does not receive the contents of a third-party review merely because a person accessed the review platform through Chhaap, unless a separate integration expressly provides that information.
Website forms
Where a participating business uses a Chhaap-hosted website or form, Chhaap may process information submitted through that form on behalf of the business.
The form should explain where appropriate which business will receive the information and the purpose for which it is being requested.
Billing information
If a Business Customer purchases a paid Chhaap service, we may receive:
- billing name;
- billing address where applicable;
- subscription plan;
- invoice information;
- payment status;
- transaction identifiers; and
- limited payment metadata.
Where a specialist payment provider processes card details, Chhaap does not need to store complete payment-card numbers itself.
Device and service information
We may automatically receive information such as:
- IP address;
- browser and device type;
- operating system;
- timestamps;
- requested pages;
- service logs;
- error information;
- security events; and
- cookie or similar identifiers where used.
We use this information for operation, security, troubleshooting and service improvement.
4. Information we do not intentionally request
Chhaap is designed as a local-business and loyalty platform.
We do not intentionally ask customers to provide sensitive information such as health records, biometric data, political opinions, religious beliefs or government identity documents unless a future feature clearly requires it and appropriate protections are introduced.
Please do not place unnecessary sensitive information into free-text fields.
5. How we collect information
We may collect information:
- directly from you;
- from a Business Customer;
- when a staff member uses Chhaap;
- when you join or use a loyalty program;
- when a QR or NFC interaction occurs;
- when you use a Wallet feature;
- when you contact support;
- when you submit a website form;
- automatically through normal server and security logs; or
- from a third-party service where you have authorised the connection.
6. Why we use information
We may use personal information to:
- create and manage accounts;
- operate loyalty programs;
- record visits, stamps and rewards;
- issue and update customer cards;
- provide Wallet functionality;
- authenticate staff;
- operate QR and NFC features;
- provide merchant websites;
- process subscriptions;
- provide support;
- detect fraud or unauthorised activity;
- maintain platform security;
- diagnose faults;
- send important service communications;
- maintain transaction and audit records;
- comply with legal obligations;
- improve Chhaap; and
- send marketing where we have a lawful basis and any required consent.
We do not use loyalty customer information to sell personal information to advertisers.
7. Marketing communications
Joining a Chhaap-powered loyalty program does not automatically mean a customer has agreed to receive promotional marketing.
Where express marketing consent is required, it should be requested separately.
Marketing messages sent through Chhaap must include applicable sender identification and unsubscribe or opt-out options.
A participating business is responsible for ensuring it has the necessary permission to send marketing communications to its customers.
Chhaap may send Business Customers information about Chhaap where permitted by law. Recipients may opt out of promotional communications using the unsubscribe method provided.
Important operational messages concerning an account, security, loyalty activity or service functionality may still be sent where necessary to provide the service.
8. Who we may disclose information to
Depending on the service being used, information may be disclosed to:
- the participating business whose loyalty program you use;
- authorised staff of that business;
- companies that provide hosting, databases, authentication, email delivery, monitoring or infrastructure;
- payment providers;
- Apple or Google where Wallet functionality is requested;
- service providers helping us operate Chhaap;
- professional advisers such as lawyers or accountants;
- regulators, law-enforcement agencies or courts where required or authorised by law; or
- a successor organisation as part of a genuine sale, merger or restructuring of the Chhaap business.
Service providers are given access only where reasonably necessary for the service they provide.
Chhaap does not sell personal information.
9. Current technology providers
Chhaap currently uses technology providers that may include:
- Supabase for database, authentication and related backend services;
- Vercel for web application hosting and delivery;
- email delivery providers such as Resend;
- Apple for Apple Wallet features;
- Google for Google Wallet and Google Business Profile-related interactions; and
- payment providers where paid subscriptions are enabled.
This list may change as our infrastructure evolves.
We assess service providers having regard to security, reliability and privacy requirements.
10. Overseas processing and disclosure
Some technology providers used by Chhaap may process or make information accessible outside Australia.
Based on Chhaap's current production configuration, information may be processed or accessible in:
Australia and the United States
Where Australian privacy law applies, we take reasonable steps appropriate to the circumstances when dealing with overseas service providers.
Our infrastructure may change, and we will update this policy where our regular overseas disclosure arrangements materially change.
12. Data retention
We retain personal information only for as long as reasonably required for:
- providing Chhaap;
- maintaining an active loyalty program;
- customer support;
- security;
- fraud prevention;
- resolving disputes;
- accounting;
- audit records; or
- legal obligations.
Some loyalty transaction records may need to be retained to preserve an accurate transaction history or investigate fraud or disputes.
Where personal information is no longer reasonably required, we take reasonable steps to delete it or de-identify it, subject to legal and legitimate operational requirements.
Backups may retain information for a limited additional period before being overwritten through normal backup processes.
13. Security
Chhaap takes reasonable technical and organisational steps to protect information against:
- unauthorised access;
- misuse;
- interference;
- loss;
- unauthorised modification; and
- unauthorised disclosure.
Measures may include access controls, tenant separation, authentication controls, secure communication, database security rules, audit records and monitoring appropriate to the relevant feature.
No internet service can guarantee absolute security.
If you believe Chhaap information or a credential has been compromised, contact support@chhaap.app.
14. Data breaches
We maintain processes for investigating suspected data breaches.
Where the Australian Notifiable Data Breaches scheme or another applicable law requires notification, we will take appropriate steps to notify affected individuals and the relevant regulator.
We may also notify users about a security incident where we believe doing so is appropriate even if mandatory notification requirements do not apply.
15. Accessing or correcting your information
You may request access to personal information Chhaap holds about you or ask us to correct information that is inaccurate.
Contact:
If information is primarily controlled by a participating business, we may refer the request to that business or work with the business to respond.
We may need to verify your identity before providing access or making significant changes.
16. Deleting information
You may contact us to request deletion of personal information.
Whether particular information can immediately be deleted depends on:
- the nature of the information;
- whether a participating business needs it to operate the loyalty program;
- legitimate security or fraud-prevention requirements;
- transaction integrity;
- legal retention requirements; and
- whether the information can instead be safely de-identified.
Where appropriate, Chhaap may de-identify records rather than destroy records that need to remain for legitimate audit or transaction-integrity purposes.
17. Loyalty cards and lost devices
If a loyalty card or Wallet pass is associated with a lost or compromised device or link, contact the relevant participating business or Chhaap.
Where technically available, an affected credential may be revoked or replaced while preserving legitimate loyalty history.
18. Third-party links
Chhaap may link to third-party websites and services including Google, Apple, social networks and participating businesses.
Those organisations control their own services and privacy practices.
This Privacy Policy does not govern information independently collected by those third parties.
19. Privacy complaints
If you believe Chhaap has mishandled your personal information, please contact:
Please explain the issue and provide enough information for us to investigate.
We will consider privacy complaints in good faith and respond within a reasonable period.
If the Australian Privacy Act applies to Chhaap and you are not satisfied with our response, you may have the right to contact the Office of the Australian Information Commissioner.
20. Changes to this Privacy Policy
We may update this Privacy Policy when:
- Chhaap introduces new features;
- our technology providers change;
- our data practices change; or
- legal requirements change.
The current version will be published on chhaap.app/privacy and will show its effective date.
If a change materially affects how we use personal information, we will take reasonable steps to provide additional notice where appropriate.