Privacy Policy

Last updated: March 6, 2026  |  Version: 2.0

This Privacy Policy explains how Points4cash Ltd ("Company," "we," "us," or "our") collects, uses, discloses, stores, and otherwise processes personal data when you use Document Reader: PDF Editor (the "App"), our related websites, customer-support channels, and any other services that link to this Privacy Policy (collectively, the "Services").

Please read this Privacy Policy carefully before using the Services.

Contents

  1. Who We Are
  2. Scope
  3. Categories of Personal Data We Collect
  4. Sources of Personal Data
  5. Why We Process Personal Data
  6. Legal Bases for Processing
  7. How We Share Personal Data
  8. Sale, Sharing & Opt-Out Rights
  9. Data Retention
  10. Your Privacy Rights
  11. Complaint to a Supervisory Authority
  12. California Privacy Notice (CCPA/CPRA)
  13. Virginia Privacy Rights (VCDPA)
  14. Colorado Privacy Rights (CPA)
  15. Connecticut Privacy Rights (CTDPA)
  16. GDPR / EEA / UK Notice
  17. Brazil LGPD Notice
  18. South Korea PIPA Notice
  19. App Permissions and Device Access
  20. SDKs and Third-Party Libraries
  21. International Data Transfers
  22. Data Security
  23. Children's Privacy
  24. Third-Party Services and Links
  25. Account Deletion and Data Deletion
  26. Changes to This Privacy Policy
  27. Contact Us

1. Who We Are

Data Controller
Points4cash Ltd
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom

Privacy Contact
Email: seon.geon@tecgames.org

Data Protection Officer (DPO)
Name: Data Protection Officer
Email: seon.geon@tecgames.org
Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

EU / UK Representative
Points4cash Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: seon.geon@tecgames.org

2. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed when you:

3. Categories of Personal Data We Collect

The following table summarizes all categories of personal data we collect or receive. We update this table whenever we add new data types, integrations, endpoints, or SDKs that result in new data collection.

Category Examples of Data Collected Purpose
Account & Profile Information Name, username, email address, phone number, account ID, user ID, referral code, login credentials, authentication data Account creation, authentication, service delivery
Device & Technical Information Device ID, advertising ID, Android ID, app instance ID, push token; IP address; device model, OS version, language, time zone, network type, carrier, app version, SDK version App functionality, security, fraud prevention, analytics
Geolocation Data Approximate or precise geolocation (GPS/network-based), where enabled by you or required for a feature Feature delivery, offer eligibility, fraud prevention
Installed Applications List or metadata of applications installed on your device Offer eligibility, fraud prevention, rewards attribution
Usage & Activity Data App interactions, session times, feature usage, clicks, views, screen events, reward events, gameplay events, survey participation, offer completion data; transaction history, reward balances, redemption history, virtual currency activity Service improvement, personalization, rewards processing
Crash, Diagnostic & Log Data Crash reports, ANRs, error logs, performance data, diagnostics App stability, debugging, service improvement
Contacts Contact names, phone numbers, or email addresses from your device's contacts list, only when you grant permission and a specific feature requires it (e.g., referral features) Referral programs, user-initiated sharing features
Text Messages (SMS) Phone number, SMS content or metadata, only when you grant SMS permission for a specific feature (e.g., phone-number verification, OTP, referral SMS) Phone verification, OTP delivery, referral features
File & Storage Access File names, file types, file metadata from documents you open or import into the App via the Storage Access Framework or explicit user selection. We do not broadly scan or index your storage. Core document reader/editor functionality
Communications & User-Submitted Content Messages you send us; support requests and attachments; survey responses, feedback, contest entries Customer support, product improvement
Health Information Health-related data only if you voluntarily submit it or a specific feature explicitly requires it, disclosed to you at the time of collection Feature-specific functionality with explicit consent
Sensitive Personal Information Precise geolocation; health data; any other sensitive data categories where permitted by law and necessary for a disclosed purpose Feature-specific, with consent where required by law
Advertising & Attribution Data Advertising identifiers (e.g., Google GAID), attribution event data, campaign IDs, conversion data, ad engagement signals Ad measurement, offer attribution, fraud detection
Third-Party Partner Data Conversion data, campaign data, device identifiers, completion status, payout data, anti-fraud signals received from advertising, attribution, analytics, offerwall, and survey partners Rewards processing, fraud prevention, offer attribution
Notice of Updates: When new endpoints, SDKs, permissions, or data types are detected or introduced in the App, we review and update this Privacy Policy accordingly. If you notice a discrepancy, please contact us immediately at seon.geon@tecgames.org.

4. Sources of Personal Data

5. Why We Process Personal Data

6. Legal Bases for Processing (EEA / UK / Similar Jurisdictions)

If you are in the EEA, UK, or another jurisdiction requiring a legal basis, we rely on one or more of the following:

7. How We Share Personal Data

We may share personal data with the following categories of recipients:

We contractually require service providers not to use your personal data for their own independent purposes beyond what is permitted by contract and applicable law.

8. Sale, Sharing, Targeted Advertising & Your Opt-Out Rights

Important: This section explains clearly whether we sell or share your personal data, and how you can opt out. Please read carefully.

8.1 Do We Sell Personal Data?

We do not sell personal data for money in the traditional sense. However, certain disclosures of identifiers, device information, advertising identifiers, usage data, precise location data, and similar data to advertising networks, attribution partners, analytics providers, monetization partners, and offerwall operators may constitute a "sale" under the broad definition used in California law (CCPA/CPRA) and certain other state laws. We treat those disclosures as "sales" for purposes of this Privacy Policy and your opt-out rights.

8.2 Do We Share Personal Data?

Yes. We do share personal data with third parties for cross-context behavioral advertising (i.e., targeted advertising). This includes sharing advertising identifiers, device identifiers, usage data, geolocation signals, and app activity data with advertising and attribution partners so they can serve ads targeted to your interests. Under California law, this constitutes "sharing" personal data. We disclose this to you transparently.

8.3 Categories of Data Sold or Shared

Category of Personal Data Sold? Shared for Targeted Advertising? Disclosed to Third Parties?
Advertising identifiers (GAID, etc.) Possibly (broad definition) Yes Yes
Device identifiers Possibly (broad definition) Yes Yes
IP address Possibly (broad definition) Yes Yes
Usage and activity data Possibly (broad definition) Yes Yes
Approximate location Possibly (broad definition) Yes Yes
Installed apps data Possibly (broad definition) No Yes (fraud prevention / attribution only)
Account / profile information No No Service providers only
Contacts / SMS data No No No (not shared with advertisers)
Health / sensitive information No No No (unless you explicitly consent)

8.4 Your Right to Know

You have the right to know:

8.5 Your Right to Opt Out of Sale or Sharing

You have the right to opt out of the sale of your personal data and the sharing of your personal data for targeted advertising purposes. This right applies to California residents (CCPA/CPRA), Colorado residents (CPA), Connecticut residents (CTDPA), Virginia residents (VCDPA), Utah residents (UCPA), and residents of other jurisdictions where such opt-out rights exist.

🛑 How to Opt Out of Sale or Sharing of Your Personal Data

You may exercise your opt-out right using any of the following methods:

After you opt out, we will stop selling or sharing your personal data for targeted advertising within 15 business days of receiving a verifiable request. We may continue to disclose information to service providers where strictly necessary to operate, secure, and maintain the Services, detect fraud, process transactions, and comply with legal obligations.

We will not discriminate against you for exercising your opt-out rights.

9. Data Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention periods may vary:

Data TypeRetention Period
Account informationWhile your account is active + up to 3 years after closure
Transaction and reward recordsUp to 7 years for accounting, fraud prevention, and audit
Support communicationsUp to 3 years after resolution
Security logs and device identifiersUp to 2 years for fraud detection and operational security
Advertising and analytics dataUp to 13 months or as required by partner agreements
Marketing dataUntil you opt out or withdraw consent
Deletion request recordsMinimal records to document compliance and prevent re-collection

When we no longer need personal data, we delete, anonymize, or securely dispose of it in accordance with applicable law.

10. Your Privacy Rights

Depending on your jurisdiction, you may have the right to:

To exercise any right, contact us at:

We may verify your identity before processing your request. We will respond within the timeframe required by applicable law (typically 30–45 days).

11. Right to Lodge a Complaint with a Supervisory Authority

If you are in the EEA, UK, South Africa, or another jurisdiction that provides this right, you have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law. In the UK, this is the Information Commissioner's Office (ICO). In the EEA, you may contact the supervisory authority in your country of residence.

We encourage you to contact us first so we can address your concern directly.

12. California Privacy Notice (CCPA / CPRA)

This section applies to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).

12.1 Categories of Personal Information Collected (Last 12 Months)

12.2 Purposes for Collection

See Section 5 above.

12.3 Sale and Sharing

We may sell or share personal information (as defined under California law) as described in Section 8. California residents have the right to opt out — see Section 8.5.

12.4 California Privacy Rights

California residents may have the following rights:

To submit a request: seon.geon@tecgames.org (Subject: "California Privacy Request").

Authorized agents may submit requests on your behalf with verifiable written authorization.

13. Virginia Privacy Rights (VCDPA)

This section applies to Virginia residents under the Virginia Consumer Data Protection Act (VCDPA).

Virginia residents may have the following rights, subject to exceptions:

To exercise your Virginia rights, contact us at seon.geon@tecgames.org (Subject: "Virginia Privacy Request"). To appeal a denied request, use the same email with subject "Virginia Privacy Appeal."

14. Colorado Privacy Rights (CPA)

Colorado residents may have rights under the Colorado Privacy Act including rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising and sale of personal data, and opt out of profiling. To exercise these rights, contact us at seon.geon@tecgames.org (Subject: "Colorado Privacy Request").

15. Connecticut Privacy Rights (CTDPA)

Connecticut residents may have rights under the Connecticut Data Privacy Act including rights to access, correct, delete, portability, opt out of targeted advertising, opt out of sale of personal data, and appeal denied requests. Contact us at seon.geon@tecgames.org (Subject: "Connecticut Privacy Request").

16. GDPR / EEA / UK Notice

If GDPR, UK GDPR, or equivalent legislation applies to you, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and the right to withdraw consent (Art. 7(3)). You also have the right to lodge a complaint with a supervisory authority (Art. 77). Our lawful bases for processing are described in Section 6.

Where we rely on legitimate interests (Art. 6(1)(f)), you may object to processing. Where we rely on consent, you may withdraw it at any time without affecting prior processing.

Contact our DPO at seon.geon@tecgames.org for GDPR-related requests.

17. Brazil LGPD Notice

If you are in Brazil, you may have rights under the Lei Geral de Proteção de Dados (LGPD), including rights to confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, revocation of consent, review of automated decisions, and the right to lodge a complaint with the ANPD. Contact us at seon.geon@tecgames.org.

18. South Korea PIPA Notice

If you are in South Korea, you may have rights under the Personal Information Protection Act (PIPA). You have the right to know whether your personal information is provided to or processed by third parties, to request access, correction, deletion, and suspension of processing, and to know whether your data is sold, shared, or entrusted to third parties. Contact us at seon.geon@tecgames.org.

19. App Permissions and Device Access

The App may request the following device permissions, used only as described:

Permission Why It Is Requested Is It Mandatory?
INTERNET Core app connectivity, syncing, analytics, ads Yes
Camera (pre-installed / system) Scanning documents or capturing images for import; uses system camera only — no background access No (only when you initiate a scan)
Location (approximate / precise) Geolocation-dependent features, fraud prevention, offer eligibility No (you may decline)
READ_CONTACTS Referral features (only when you explicitly use the referral feature) No
READ_SMS / RECEIVE_SMS OTP / phone number verification (only for verification flows) No
RECEIVE_BOOT_COMPLETED / notifications Push notification delivery No
READ_EXTERNAL_STORAGE (android:maxSdkVersion="28") Retained only for compatibility with Android 8 and below (SDK < 28). On Android 9 (SDK 28) and above, the App uses the Storage Access Framework (SAF) and the Photo and Video Picker, which do not require this permission. We have set android:maxSdkVersion="28" so this permission is not granted on modern devices. No broad scanning of your storage occurs. Legacy only (Android ≤ 8)
Photos & Videos access The App uses the Android system Photo Picker (no broad media access required) No

You can manage and revoke most permissions at any time in your device's Settings → Apps → [App Name] → Permissions.

20. Third-Party SDKs and Libraries

The App integrates third-party SDKs for analytics, advertising, attribution, crash reporting, fraud prevention, monetization, and similar functions. These SDKs may independently collect data from your device subject to their own privacy policies. We review and update this section when new SDKs are added.

SDK Category Purpose May Collect
Analytics SDKs App usage analytics, crash reporting, performance monitoring Device ID, usage events, crash data
Advertising SDKs Serving ads, ad targeting, frequency capping Advertising ID, IP, usage signals
Attribution / MMP SDKs Measuring campaign effectiveness, install attribution Device ID, advertising ID, install events
Offerwall / Monetization SDKs Delivering offer tasks, reward campaigns Device ID, installed apps (where applicable), completion events
Anti-Fraud / Security SDKs Detecting fraud, abuse, and bot activity Device fingerprint, network info, behavioral signals
Support / Communication SDKs In-app customer support chat Account info, messages

We only integrate SDKs that are up-to-date and have no known critical security issues. We do not use SDKs that have been flagged as "outdated" or having critical vulnerabilities. When new SDKs are detected in the App, we review their data collection practices and update this Privacy Policy accordingly.

21. International Data Transfers

Your personal data may be transferred to and processed in countries other than your country of residence, including the United Kingdom, the United States, and other countries where our service providers operate. Where required by law (e.g., GDPR), we implement appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms.

22. Data Security

We implement reasonable technical, administrative, and organizational security measures — including encryption in transit and at rest — to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. We do not transmit personal data unencrypted. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your data has been compromised, contact us immediately.

23. Children's Privacy

The Services are not directed to children under 13 (or under 16 in the EEA/UK or such higher age as required by applicable law) unless expressly stated otherwise. We do not knowingly collect personal data from children below the applicable age threshold. We do not knowingly sell or share the personal data of children. If you believe a child has provided personal data to us, please contact us at seon.geon@tecgames.org and we will take prompt action to delete it.

24. Third-Party Services and Links

The Services may contain links to third-party websites, offer providers, survey platforms, or partner services. Their privacy practices are governed by their own privacy policies. We are not responsible for third-party privacy practices and encourage you to review them before interacting with any third party.

25. Account Deletion and Data Deletion

You may request deletion of your account and associated personal data by:

We will process your deletion request within the timeframe required by applicable law. We may retain certain information after deletion where necessary for fraud prevention, legal compliance, tax/accounting obligations, dispute resolution, security, or enforcement of our agreements, as permitted by law.

26. Changes to This Privacy Policy

We review and update this Privacy Policy at least annually and whenever there are material changes to our data practices — including the addition of new endpoints, SDKs, permissions, or data types. When we make material changes, we will post the updated version here and revise the "Last updated" date. For significant changes affecting your rights, we will provide additional notice (e.g., in-app notification or email) and, where required by law, obtain your consent.

27. Contact Us

For any questions, requests, or concerns about this Privacy Policy or our privacy practices:

Points4cash Ltd
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Email: seon.geon@tecgames.org
Support: seon.geon@tecgames.org

We aim to respond to all privacy-related inquiries within 30 days of receipt.