Privacy Policy

Last updated

This policy explains what I Totally Need That LLC, doing business as Max My Points (“MaxMyPoints,” “we,” “us”) collects when you use MaxMyPoints, why, who we share it with, how long we keep it, and the rights you have over it.

The short version. We read your card transactions so we can tell you which card you should have used. We do not sell your data, and we do not share it for advertising. We never receive your bank login credentials, and our access to your accounts is read-only. We do not run advertising or analytics trackers on this site. You can delete a card, a statement, or your whole account yourself, at any time, and the underlying data goes with it.

1. Who this covers

This policy applies to maxmypoints.app and the MaxMyPoints service. If your seat was purchased for you by an organisation such as a financial advisory firm, Section 7 explains what that organisation can and cannot see.

2. What we collect

Information you give us

If you join the launch list

Our launch page lets you leave an email address to hear about our Product Hunt launch. This is separate from having an account — you can join the list without one, and joining it does not create one. We store only your email address, the date, the page you joined from, the IP address the signup came from, and the exact sentence you agreed to at the time. We do not ask for your name and we collect nothing else.

We use it to send you one email, on launch day. We do not add you to any other mailing, and we do not share the list. Every message carries an unsubscribe link, and you can also reply to it or write to us at the address in Section 18 to be removed.

Information from your connected accounts

We request only the data needed to compute your audit. We do not collect account balances for investment or deposit accounts, income, employment history, or your credit report.

Information generated as you use the service

3. Financial account connections and Plaid

When you connect a card or bank account, you do so through Plaid. Plaid handles the connection to your institution and passes us the transaction data you authorise.

4. Statement uploads

If you upload a statement, the file is stored only for as long as it takes to extract the transaction fields we need — date, merchant, amount and category — and is then deleted from our storage. We keep the extracted transactions, not the document. We do not use your statements for any purpose other than producing your audit.

5. How we use your information, and why

PurposeData used
Compute your rewards audit, comparisons and recommendationsTransactions, cards, settings
Run the tools you enable — fee analysis, welcome-offer tracking, benefit windowsCards, transactions, settings
Send you the alerts and reminders you have turned onEmail, preferences, audit results
Take payment, manage your plan, and handle refundsBilling records, email
Provide support and respond to youWhatever you send us, account details
Keep the service secure, prevent fraud and abuse, and debug faultsTechnical and security data
Meet legal obligations and prove consentConsent and billing records
Improve the product and our rewards catalogueAggregated and de-identified data only — see below

De-identified and aggregated data. We may produce statistics that cannot reasonably be used to identify you — for example, how often a merchant is miscategorised across all users, or how much value a card returns on average — and use them to improve the service and its catalogue. We do not attempt to re-identify this data, and we do not sell it.

We do not use your transaction data to train third-party artificial intelligence models. Our automated catalogue checks read publicly published card terms from issuer websites; no customer data is sent to those systems.

No automated decisions with legal effect. Our recommendations are suggestions. We make no decision about your credit, and no decision that produces a legal or similarly significant effect on you.

6. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. We have not done so in the preceding twelve months.

We share information only with service providers who process it on our instructions, under contract, and only as needed to run the service:

ProviderWhat it handles
SupabaseDatabase, authentication, file storage and server functions — our core infrastructure
PlaidConnections to your financial institutions (policy)
StripePayment processing and subscription billing (policy)
VercelHosting and delivery of the website itself
ResendSending transactional and alert email
BrevoSending the launch-list email described in Section 2, to addresses on that list only (policy)
Content delivery networksServing fonts and JavaScript libraries. These receive your IP address as part of loading the page.

We may also disclose information when required by law, valid legal process, or to protect the rights, safety or property of you, us or others; and to a successor in connection with a merger, acquisition or sale of assets, in which case we will notify you and this policy will continue to apply until replaced.

7. If your seat was provided by an organisation

Where a firm — for example your financial advisor — has purchased a seat for you, that firm becomes able to see limited information about your account, but only to the extent you separately and explicitly consent, and only at the level of detail you approve. You are shown exactly what will be visible before you agree.

8. Card applications and referral compensation

If you click through to apply for a card, we record that the click happened and whether it converted, because we may be paid a commission by the issuer. We disclose this wherever such a link appears. We do not send the issuer your transaction data. Anything you submit on the issuer’s own site is governed by the issuer’s privacy policy, not ours.

9. Cookies and similar technologies

We do not use advertising cookies, and we run no analytics or tracking pixels on this site. We use browser storage to keep you signed in, to remember your preferences, and to hold the name of the short link you arrived through for up to 30 days (Section 2). Because we do not track you across sites, there is nothing here to opt out of; we honour Global Privacy Control signals regardless.

10. How long we keep it

DataRetention
Uploaded statement filesDeleted once the transactions are extracted
Transactions, cards, auditsUntil you delete the card, the statement or your account
Account and profileUntil you delete your account
Billing and tax recordsUp to 7 years after the transaction, as tax and accounting law requires
Consent recordsAt least 3 years, to evidence the consent you gave
Launch-list email addressUntil you unsubscribe or ask us to remove it, and no later than 90 days after the launch it was collected for
Security and error logsTypically under 90 days
De-identified and aggregated statisticsIndefinitely — these no longer identify you

11. Deleting your data

You are in control and you do not need to ask us:

We retain only what Section 10 says we must — principally billing records and proof of consent — and backups are overwritten on their normal cycle.

12. Security

We maintain administrative, technical and physical safeguards appropriate to the sensitivity of this data, including encryption in transit and at rest, row-level access control in the database so one account cannot read another’s data, restricted and multi-factor-protected administrative access, and logging of privileged actions. Our Security page describes this in more detail.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulators as the law requires.

When we get it wrong

This policy describes how the service is built to behave, and we hold ourselves to it. It is also software, and software has defects. A bug may occasionally cause data to be handled differently from what is described here — a file kept longer than it should have been, a deletion that did not complete, a log line that captured more than intended.

We treat that as a fault to fix, not as a change to this policy. When we find one, or you report one, we will correct the underlying defect, remove or delete any data that should not have been retained, and tell you and the relevant regulators where the law requires it. We would much rather hear about it than not: support@maxmypoints.app.

Nothing in this section reduces the rights you have under Section 13 or under applicable law. Our financial responsibility for any failure of the service is addressed in the Terms of Service, not here.

13. Your privacy rights

Depending on where you live, you may have the right to:

These rights are available to residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, among others, subject to each state’s own rules and exceptions.

How to exercise them

Use Account to download a portable copy of everything we hold about you, or to delete your account and its data. For anything else, or if you would rather not do it yourself, email support@maxmypoints.app. We will verify your identity through your account email before acting, and respond within the time the law allows — generally 45 days, extendable once. An authorised agent may submit a request with proof of authorisation.

Appeals

If we decline your request, you may appeal by replying to our decision or emailing support@maxmypoints.app with “Appeal” in the subject. We will respond with our reasoning. If you remain dissatisfied you may complain to your state Attorney General.

14. California: sensitive information and financial data

Financial account information is treated as sensitive personal information under California law. We collect it only to provide the service you requested, and we do not use or disclose it to infer characteristics about you.

Some of the information we handle is nonpublic personal information subject to the federal Gramm-Leach-Bliley Act, and information governed by that Act is exempt from certain state privacy laws. Where an exemption applies, we still apply the practices described in this policy.

15. Children

MaxMyPoints is not directed to children. You must be 18 or older to use it, and we do not knowingly collect information from anyone under 18. If we learn we have, we will delete it. Contact support@maxmypoints.app if you believe a child has given us information.

16. Where your data is processed

We are based in the United States and process and store data there. The service is intended for users in the United States. If you access it from elsewhere, you understand that your information will be processed in the United States, where privacy laws may differ from those of your country.

17. Changes to this policy

We may update this policy. Each version carries the date shown at the top of this page. If we make a material change we will notify you by email or ask you to accept the new version when you next sign in. You can see which version you accepted, and when, in Account.

18. Contact us

I Totally Need That LLC d/b/a Max My Points
1909 E Ray Rd, Ste 9 - 1033
Chandler, AZ 85225
support@maxmypoints.app

One address reaches us for everything. So that requests with a statutory deadline are not missed, please put the topic in the subject line — Privacy request, Privacy appeal or Security. The links on this page do that for you.