Legal

Privacy Policy

Last updated: April 2026

Introduction

Privi ("we", "us", or "our") operates the private membership platform accessible at privi.club (the "Service"). This Privacy Policy explains what information we collect when you use Privi, how we use it, and the choices available to you. By creating an account or adding your Privi pass to Apple Wallet or Google Wallet, you acknowledge that you have read and understood this policy. If you do not agree, please do not use the Service. Privi is operated from Quebec, Canada.

Information We Collect

We collect the following categories of information: Account Information. When you accept an invitation and create your Privi account, we collect your email address and name. These are used to identify you within the platform and to issue your wallet pass. Wallet Pass Data. We generate and maintain a digital wallet pass associated with your account. This includes your display name, membership tier, credit balance, and a unique member identifier embedded in the pass. Usage Data. We record how you interact with the Service — perks you view, redemptions you complete, referral links you generate, and brands you engage with. This data informs your tier status and personalizes your experience. Brand Interaction Data. When you redeem a perk or scan in at a brand location, a record of that interaction is stored and shared (in aggregated form) with the relevant brand partner. Referral Activity. If you invite others using a referral link, we track which new members joined through your invitation to credit your account and maintain the integrity of the referral system. Device Information. We collect basic device identifiers and operating system information to deliver wallet passes correctly and to troubleshoot technical issues. Location Data. If you enable location-based perks, your approximate location may be used to surface geo-triggered offers when you are near a partner location. This is done via the native wallet pass geofence feature on your device — we do not continuously track your location.

How We Use Your Information

We use the information we collect for the following purposes: To Provide the Service. Your account information and pass data are necessary to issue and maintain your Privi wallet pass, calculate your tier, and deliver perks. To Personalise Your Experience. We use your usage history and brand interactions to surface perks most relevant to you and to determine eligibility for tier-specific offers. To Send Notifications. We use your pass data to send push notifications directly to your wallet pass — new perks, tier upgrades, and platform announcements. You can opt out at any time through your device's wallet settings. Analytics and Improvement. Aggregated, anonymised usage data helps us understand how the platform is used and where we can improve. We do not use individual-level data for advertising. Legal and Security. We may use your data to detect fraud, enforce our Terms of Use, and comply with applicable legal obligations.

Information Sharing

We do not sell your personal data. We share information only in the following limited circumstances: Brand Partners. Brand partners receive aggregated and anonymised analytics about perk performance — such as how many members redeemed an offer. Individual member data is not shared with brands unless you explicitly take an action (such as scanning in at a location) that by its nature records your presence. Service Providers. We use third-party services to operate the platform, including Google Firebase (database, authentication, cloud functions), Apple and Google Wallet APIs (pass delivery), and AWS SES or a similar provider for transactional email. These providers process data on our behalf and are bound by data processing agreements. Legal Requirements. We may disclose your information if required to do so by law, court order, or a government authority, or if we believe disclosure is necessary to protect the rights or safety of Privi, its members, or the public.

Data Storage & Security

Your data is stored on Google Cloud infrastructure (Firebase Firestore and Cloud Storage), which is hosted primarily in North America. Google Cloud maintains industry-standard security certifications including ISO 27001 and SOC 2. All data is encrypted in transit using TLS and encrypted at rest by default. Access to production data is restricted to authorised team members only, and access is logged. While we take reasonable measures to protect your information, no system is completely secure. We encourage you to protect your email account, as it is the primary way you access Privi.

Your Rights

You have the following rights regarding your personal data: Access. You may request a copy of the personal information we hold about you by contacting hello@privi.club. Correction. If any of your information is inaccurate, you may request that we correct it. Deletion. You may request that we delete your account and associated personal data. Deletion requests are processed within 30 days. Note that some information may be retained in anonymised, aggregated form. Data Export. You may request an export of your personal data in a machine-readable format. Opt Out of Notifications. You can disable wallet push notifications at any time through your device's built-in wallet settings (Apple Wallet or Google Wallet) without deleting your account. To exercise any of these rights, email hello@privi.club with the subject line "Privacy Request".

Cookies

We use cookies and similar technologies on a limited basis: Invite and Referral Tracking. When you arrive via a referral or invite link, a short-lived cookie stores the invite code so it is not lost if you navigate away before completing sign-up. Session. A session cookie maintains your authenticated state while using the web interface. We do not use third-party advertising cookies or cross-site tracking pixels. We do not participate in any ad networks.

Children

Privi is not directed at individuals under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a minor has provided us with their information, please contact hello@privi.club and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last Updated" date below and, where appropriate, send a notification to your wallet pass. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

Contact

If you have any questions, concerns, or requests related to this Privacy Policy, please contact us at: hello@privi.club We aim to respond to all privacy inquiries within 5 business days.