Privacy Policy

What we collect, where it is stored, what each store you join can see, how ads work on the Free plan, and how you can have your data removed.

Last updated: October 10, 2026

1. Introduction

Welcome to Design Scribe Solutions (“App”, “we”, “us”, or “our”). We provide a SaaS platform for creating and managing custom loyalty and membership programs. This policy explains how we handle your data when you use our mobile application, including how it is stored and how advertising works in apps on the Free plan.

2. Information We Collect

We limit data collection to only what is necessary to provide our membership services.

Personal Information

  • Full Name: For member identification and profile creation.
  • Email Address: For account login, support, and security notifications.
  • Mobile Number: For account verification and member communication.
  • Password: Never stored in readable form; used only to sign you in.
  • Stores You Join: The businesses whose loyalty programs you asked to join, and whether each one approved your request.

Loyalty Activity

  • Your stamps, points, and rewards at each store you are a member of.
  • Transactions: the products or rewards involved, the points earned or used, the date, and the cashier who served you.
  • QR code scans and voucher redemptions, including which account scanned them and when.
  • Basic interaction logs (e.g., login timestamps) to provide analytics to program administrators.

Cashier Accounts

  • If you sign in as a cashier, your account is created and managed by the store you work for. We record which cashier created each QR code and served each transaction.

Stored on Your Device

  • The store you last opened, its branding, a copy of your card and history for faster loading, your sign-in session, and your light or dark mode choice. Your card, history, and sign-in session are removed when you log out.

Advertising Data (Free plan apps only)

  • Device and advertising identifiers, IP address, approximate location, and ad interaction data, collected by our advertising partners when an ad is shown. See section 6.

3. How We Use Your Information

  • To create and maintain your account, and let you join the stores you choose.
  • To add points and redeem rewards when you scan a cashier’s QR code or use a voucher.
  • To provide real-time analytics and insights to business administrators.
  • To enable “White-Label” branding and personalized user experiences.
  • To show ads in apps on the Free plan.
  • To ensure security, prevent fraud, and comply with GDPR requirements.

4. SaaS & White-Label Relationship

We operate as a Service Provider. If you are a member of a program (e.g., a dental clinic or retail store), that business is the Data Controller.

While we provide the secure infrastructure, the individual business manages its own member list. We encourage you to review the specific privacy terms of the business offering the loyalty program.

What Each Store Can See

  • Your account is not tied to any store when you sign up. A store only sees your details after you ask to join it.
  • When you ask to join, the store receives your name, email address, and mobile number so it can approve or decline your request.
  • Once you are a member, the store and its staff (including cashiers) can see your stamps, rewards, and transactions at that store only. Stores cannot see your activity at other stores.

5. Where Your Data Is Stored

We use Google Firebase to store and process data. Our databases and most of our processing are in Google Cloud’s Singapore region (asia-southeast1). Sign-in is handled by Firebase Authentication, which Google operates globally, and some scheduled maintenance tasks run in the United States. Data is organized as follows:

  • Your profile (name, email address, mobile number) is stored once and belongs to your account, not to any one store.
  • Member data is stored in a shared Firebase project. Every record is separated by storeName, so a business’s members are kept apart from the members of every other business.
  • Staff accounts, including cashiers and store administrators, are stored with the admin data described below.
  • Admin data is stored in a different Firebase project. The admin dashboard that businesses use to manage their program runs there, not in the member project.
  • Dedicated projects: a business may have its own separate Firebase project. When it does, its members’ data is stored in that project instead of the shared one.

6. Advertising on the Free Plan

Apps on the Free plan show ads. Ads are provided by third-party advertising partners, who may collect device and advertising identifiers, your IP address, approximate location, and how you interact with ads.

  • What we do not share: your name, email address, and mobile number are not provided to advertising partners.
  • Your choices: you can reset your advertising ID or opt out of personalized ads in your device settings.
  • Consent: where the law requires it, such as in the EU and UK, we ask for your consent before ads that use your data are shown.

7. Data Protection & Security

We implement enterprise-grade security measures:

  • SSL/TLS Encryption: All data in transit is encrypted.
  • Encrypted Storage: Passwords and personal identifiers are stored using industry-standard hashing.
  • Separated Data: Member data is separated by store, and admin data is kept in its own Firebase project.
  • Access Controls: Database rules let each customer read only their own records, and let staff access only their own store’s data.
  • Server-Side Points: Points and rewards can only be changed by our servers, never directly by the app.
  • Short-Lived Codes: QR codes can be used once, expire, and are automatically deleted after one day. Cashier sign-ins expire after 24 hours.

8. Information Sharing

We do not sell or rent your personal information. We share data only with:

  • The businesses whose loyalty programs you ask to join or have joined, as described in section 4.
  • Google Firebase, which hosts our data on our behalf.
  • Advertising partners, limited to the advertising data described in section 6 and only in Free plan apps.
  • Authorities, where required by law.

9. Your Rights & Choices

Under GDPR and other data laws, you have the right to:

  • Access & Export: Request a copy of your personal data.
  • Rectification: Correct any inaccurate information.
  • Deletion: Request that we delete your account and associated data. See how to delete your account.
  • Ad choices: Opt out of personalized ads or withdraw ad consent through your device settings or the in-app consent prompt.

10. Data Retention

We retain your data only for as long as your account is active or as needed to provide services to the business administrator. QR code sessions are deleted automatically one day after they are created. If a store closes its program, its member data is permanently erased after a grace period. If an account is deleted, we remove or anonymize your data within 30 days, unless legal obligations require a longer retention period. Data held by advertising partners is governed by their own retention policies.

11. Children’s Privacy

Our App is intended for users aged 13 and older. We do not knowingly collect information from children under 13.

12. Contact Us

Email
designscribe.solution@gmail.com
Website
design-scribe-website.web.app
Facebook
Design Scribe Solutions

Your privacy is important to us

© 2026 Design Scribe Solutions. All rights reserved.