Privacy Policy
Last updated —
This policy explains what I Totally Need That LLC, doing business as Max My Points (“MaxMyPoints,” “we,” “us”) collects when you use MaxMyPoints, why, who we share it with, how long we keep it, and the rights you have over it.
The short version. We read your card transactions so we can tell you which card you should have used. We do not sell your data, and we do not share it for advertising. We never receive your bank login credentials, and our access to your accounts is read-only. We do not run advertising or analytics trackers on this site. You can delete a card, a statement, or your whole account yourself, at any time, and the underlying data goes with it.
1. Who this covers
This policy applies to maxmypoints.app and the MaxMyPoints service. If your seat was purchased for you by an organisation such as a financial advisory firm, Section 7 explains what that organisation can and cannot see.
2. What we collect
Information you give us
- Account details — your email address, and your name if you provide one. Your password is set and stored by our authentication provider; we never see it.
- Cards you tell us about — issuer, product, last four digits, opening or renewal dates, and whether the card is active. We do not collect or store full card numbers.
- Statements you upload — see Section 4.
- Your settings — notification preferences, and the tools you have enabled.
- What you send us — support messages, refund requests and feedback.
If you join the launch list
Our launch page lets you leave an email address to hear about our Product Hunt launch. This is separate from having an account — you can join the list without one, and joining it does not create one. We store only your email address, the date, the page you joined from, the IP address the signup came from, and the exact sentence you agreed to at the time. We do not ask for your name and we collect nothing else.
We use it to send you one email, on launch day. We do not add you to any other mailing, and we do not share the list. Every message carries an unsubscribe link, and you can also reply to it or write to us at the address in Section 18 to be removed.
Information from your connected accounts
- Transactions — date, merchant description, amount, and the category assigned to the charge.
- Account identifiers — the institution, the account type, a masked account number, and identifiers that let us match a transaction to the right card.
We request only the data needed to compute your audit. We do not collect account balances for investment or deposit accounts, income, employment history, or your credit report.
Information generated as you use the service
- Audit results — computed rewards, comparisons and recommendations.
- Billing records — plan, amounts paid, dates, status, and an identifier from our payment processor. We do not store your card number.
- Consent records — which version of these documents you accepted, when, the IP address the acceptance came from, and your browser’s user-agent string. We keep this as proof of consent.
- Card application clicks — that you clicked through to an issuer, and whether the referral converted. See Section 8.
- Arrival source — if you reach us through one of our own short links (for example from an advert or a social profile), we record which link, when, whether the browser looked like a phone, a desktop or an automated visitor, and the name of the site that sent you. We do not record your IP address for this, and we set no cookie. Your browser keeps the link name for up to 30 days so that, if you buy, the purchase can be credited to that link; if you create an account in that time, the link name is kept with the account for the same purpose.
- Technical and security data — IP address, request timestamps and error logs, used to keep the service running and to detect abuse.
3. Financial account connections and Plaid
When you connect a card or bank account, you do so through Plaid. Plaid handles the connection to your institution and passes us the transaction data you authorise.
- We never receive or store your banking username, password, or security answers. You enter them with Plaid or with your bank, never with us.
- Access is read-only. We cannot move money or change anything at your institution.
- Plaid’s own handling of your information is governed by its End User Privacy Policy, which we encourage you to read.
- You control each connection from Statements, with two separate actions. Pause stops a card counting toward your audit but deliberately keeps the connection open and still receiving data, so resuming restores a complete history. Disconnect ends the relationship: the card and every transaction we imported from it are deleted, and — once no other card on that same bank login remains connected — we revoke the connection at Plaid and your bank stops sharing data with us. While another card on that login is still connected the connection necessarily stays open, because it is the same single authorisation; nothing from the disconnected card is stored.
4. Statement uploads
If you upload a statement, the file is stored only for as long as it takes to extract the transaction fields we need — date, merchant, amount and category — and is then deleted from our storage. We keep the extracted transactions, not the document. We do not use your statements for any purpose other than producing your audit.
5. How we use your information, and why
| Purpose | Data used |
|---|---|
| Compute your rewards audit, comparisons and recommendations | Transactions, cards, settings |
| Run the tools you enable — fee analysis, welcome-offer tracking, benefit windows | Cards, transactions, settings |
| Send you the alerts and reminders you have turned on | Email, preferences, audit results |
| Take payment, manage your plan, and handle refunds | Billing records, email |
| Provide support and respond to you | Whatever you send us, account details |
| Keep the service secure, prevent fraud and abuse, and debug faults | Technical and security data |
| Meet legal obligations and prove consent | Consent and billing records |
| Improve the product and our rewards catalogue | Aggregated and de-identified data only — see below |
De-identified and aggregated data. We may produce statistics that cannot reasonably be used to identify you — for example, how often a merchant is miscategorised across all users, or how much value a card returns on average — and use them to improve the service and its catalogue. We do not attempt to re-identify this data, and we do not sell it.
We do not use your transaction data to train third-party artificial intelligence models. Our automated catalogue checks read publicly published card terms from issuer websites; no customer data is sent to those systems.
No automated decisions with legal effect. Our recommendations are suggestions. We make no decision about your credit, and no decision that produces a legal or similarly significant effect on you.
6. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. We have not done so in the preceding twelve months.
We share information only with service providers who process it on our instructions, under contract, and only as needed to run the service:
| Provider | What it handles |
|---|---|
| Supabase | Database, authentication, file storage and server functions — our core infrastructure |
| Plaid | Connections to your financial institutions (policy) |
| Stripe | Payment processing and subscription billing (policy) |
| Vercel | Hosting and delivery of the website itself |
| Resend | Sending transactional and alert email |
| Brevo | Sending the launch-list email described in Section 2, to addresses on that list only (policy) |
| Content delivery networks | Serving fonts and JavaScript libraries. These receive your IP address as part of loading the page. |
We may also disclose information when required by law, valid legal process, or to protect the rights, safety or property of you, us or others; and to a successor in connection with a merger, acquisition or sale of assets, in which case we will notify you and this policy will continue to apply until replaced.
7. If your seat was provided by an organisation
Where a firm — for example your financial advisor — has purchased a seat for you, that firm becomes able to see limited information about your account, but only to the extent you separately and explicitly consent, and only at the level of detail you approve. You are shown exactly what will be visible before you agree.
- The firm never signs in as you and never has access to your session.
- The firm cannot see your banking credentials, and cannot connect or disconnect accounts on your behalf.
- Every access by the firm to your data is logged, and you can see that log.
- You can withdraw that consent at any time, which stops the firm’s access from that moment. Your own account and data are unaffected, and remain yours.
8. Card applications and referral compensation
If you click through to apply for a card, we record that the click happened and whether it converted, because we may be paid a commission by the issuer. We disclose this wherever such a link appears. We do not send the issuer your transaction data. Anything you submit on the issuer’s own site is governed by the issuer’s privacy policy, not ours.
9. Cookies and similar technologies
We do not use advertising cookies, and we run no analytics or tracking pixels on this site. We use browser storage to keep you signed in, to remember your preferences, and to hold the name of the short link you arrived through for up to 30 days (Section 2). Because we do not track you across sites, there is nothing here to opt out of; we honour Global Privacy Control signals regardless.
10. How long we keep it
| Data | Retention |
|---|---|
| Uploaded statement files | Deleted once the transactions are extracted |
| Transactions, cards, audits | Until you delete the card, the statement or your account |
| Account and profile | Until you delete your account |
| Billing and tax records | Up to 7 years after the transaction, as tax and accounting law requires |
| Consent records | At least 3 years, to evidence the consent you gave |
| Launch-list email address | Until you unsubscribe or ask us to remove it, and no later than 90 days after the launch it was collected for |
| Security and error logs | Typically under 90 days |
| De-identified and aggregated statistics | Indefinitely — these no longer identify you |
11. Deleting your data
You are in control and you do not need to ask us:
- Delete next to an uploaded statement in Statements permanently removes that statement and the transactions imported from it. If nothing is left behind that card, the card record goes too.
- Disconnect on a connected card in Statements permanently removes the card and everything imported against it, and revokes the bank authorisation at Plaid once no card on that connection remains. (Pause is the reversible option — it excludes a source from your audit and deletes nothing.)
- Deleting your account in Account removes your profile, cards, transactions and audit history.
We retain only what Section 10 says we must — principally billing records and proof of consent — and backups are overwritten on their normal cycle.
12. Security
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of this data, including encryption in transit and at rest, row-level access control in the database so one account cannot read another’s data, restricted and multi-factor-protected administrative access, and logging of privileged actions. Our Security page describes this in more detail.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulators as the law requires.
When we get it wrong
This policy describes how the service is built to behave, and we hold ourselves to it. It is also software, and software has defects. A bug may occasionally cause data to be handled differently from what is described here — a file kept longer than it should have been, a deletion that did not complete, a log line that captured more than intended.
We treat that as a fault to fix, not as a change to this policy. When we find one, or you report one, we will correct the underlying defect, remove or delete any data that should not have been retained, and tell you and the relevant regulators where the law requires it. We would much rather hear about it than not: support@maxmypoints.app.
Nothing in this section reduces the rights you have under Section 13 or under applicable law. Our financial responsibility for any failure of the service is addressed in the Terms of Service, not here.
13. Your privacy rights
Depending on where you live, you may have the right to:
- Know and access the personal information we hold about you, including the categories, sources, purposes and recipients;
- Correct inaccurate information;
- Delete your information;
- Obtain a portable copy in a usable format;
- Opt out of sale, sharing for targeted advertising, or profiling with legal effects — none of which we do;
- Limit the use of sensitive personal information — we use it only to provide the service you asked for, which is a purpose the law already permits;
- Not be discriminated against for exercising any of these rights. We will not deny service, change prices, or reduce quality because you did.
These rights are available to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, among others, subject to each state’s own rules and exceptions.
How to exercise them
Use Account to download a portable copy of everything we hold about you, or to delete your account and its data. For anything else, or if you would rather not do it yourself, email support@maxmypoints.app. We will verify your identity through your account email before acting, and respond within the time the law allows — generally 45 days, extendable once. An authorised agent may submit a request with proof of authorisation.
Appeals
If we decline your request, you may appeal by replying to our decision or emailing support@maxmypoints.app with “Appeal” in the subject. We will respond with our reasoning. If you remain dissatisfied you may complain to your state Attorney General.
14. California: sensitive information and financial data
Financial account information is treated as sensitive personal information under California law. We collect it only to provide the service you requested, and we do not use or disclose it to infer characteristics about you.
Some of the information we handle is nonpublic personal information subject to the federal Gramm-Leach-Bliley Act, and information governed by that Act is exempt from certain state privacy laws. Where an exemption applies, we still apply the practices described in this policy.
15. Children
MaxMyPoints is not directed to children. You must be 18 or older to use it, and we do not knowingly collect information from anyone under 18. If we learn we have, we will delete it. Contact support@maxmypoints.app if you believe a child has given us information.
16. Where your data is processed
We are based in the United States and process and store data there. The service is intended for users in the United States. If you access it from elsewhere, you understand that your information will be processed in the United States, where privacy laws may differ from those of your country.
17. Changes to this policy
We may update this policy. Each version carries the date shown at the top of this page. If we make a material change we will notify you by email or ask you to accept the new version when you next sign in. You can see which version you accepted, and when, in Account.
18. Contact us
I Totally Need That LLC d/b/a Max My Points
1909 E Ray Rd, Ste 9 - 1033
Chandler, AZ 85225
support@maxmypoints.app
One address reaches us for everything. So that requests with a statutory deadline are not missed, please put the topic in the subject line — Privacy request, Privacy appeal or Security. The links on this page do that for you.