1. Security approach
We apply reasonable technical and organisational measures appropriate to the nature of each system. Controls are selected according to data sensitivity, user impact and integration risk.
2. Access control
- Role-based access for administrative and support functions.
- Controlled credentials and session handling.
- Access review when responsibilities change.
- Separation between public interfaces and administrative operations.
3. Application and API controls
- Encrypted transport through HTTPS where supported.
- Server-side validation for important requests.
- Authentication and authorization checks for protected resources.
- Structured error handling without unnecessary disclosure.
- Request identifiers and status records for critical operations.
4. Data handling
We limit access to business and user data to authorised operational purposes. Sensitive records are not intentionally published, and public pages do not display the proprietor's full tax identifier or identity number.
5. Fraud and abuse controls
Consumer engagement systems may use account, device, network and behavioural signals to detect duplicate accounts, automation, manipulated activity and other policy violations.
6. Incident reporting
Security concerns should be sent to security@rewardtechglobal.com. Please include the affected service, a clear description, relevant timestamps and safe reproduction details.