Last updated: March 6, 2026 | Version: 2.0
This Privacy Policy explains how Points4cash Ltd ("Company," "we," "us," or "our") collects, uses, discloses, stores, and otherwise processes personal data when you use Document Reader: PDF Editor (the "App"), our related websites, customer-support channels, and any other services that link to this Privacy Policy (collectively, the "Services").
Please read this Privacy Policy carefully before using the Services.
Data Controller
Points4cash Ltd
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Privacy Contact
Email: seon.geon@tecgames.org
Data Protection Officer (DPO)
Name: Data Protection Officer
Email: seon.geon@tecgames.org
Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
EU / UK Representative
Points4cash Ltd
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: seon.geon@tecgames.org
This Privacy Policy applies to personal data processed when you:
The following table summarizes all categories of personal data we collect or receive. We update this table whenever we add new data types, integrations, endpoints, or SDKs that result in new data collection.
| Category | Examples of Data Collected | Purpose |
|---|---|---|
| Account & Profile Information | Name, username, email address, phone number, account ID, user ID, referral code, login credentials, authentication data | Account creation, authentication, service delivery |
| Device & Technical Information | Device ID, advertising ID, Android ID, app instance ID, push token; IP address; device model, OS version, language, time zone, network type, carrier, app version, SDK version | App functionality, security, fraud prevention, analytics |
| Geolocation Data | Approximate or precise geolocation (GPS/network-based), where enabled by you or required for a feature | Feature delivery, offer eligibility, fraud prevention |
| Installed Applications | List or metadata of applications installed on your device | Offer eligibility, fraud prevention, rewards attribution |
| Usage & Activity Data | App interactions, session times, feature usage, clicks, views, screen events, reward events, gameplay events, survey participation, offer completion data; transaction history, reward balances, redemption history, virtual currency activity | Service improvement, personalization, rewards processing |
| Crash, Diagnostic & Log Data | Crash reports, ANRs, error logs, performance data, diagnostics | App stability, debugging, service improvement |
| Contacts | Contact names, phone numbers, or email addresses from your device's contacts list, only when you grant permission and a specific feature requires it (e.g., referral features) | Referral programs, user-initiated sharing features |
| Text Messages (SMS) | Phone number, SMS content or metadata, only when you grant SMS permission for a specific feature (e.g., phone-number verification, OTP, referral SMS) | Phone verification, OTP delivery, referral features |
| File & Storage Access | File names, file types, file metadata from documents you open or import into the App via the Storage Access Framework or explicit user selection. We do not broadly scan or index your storage. | Core document reader/editor functionality |
| Communications & User-Submitted Content | Messages you send us; support requests and attachments; survey responses, feedback, contest entries | Customer support, product improvement |
| Health Information | Health-related data only if you voluntarily submit it or a specific feature explicitly requires it, disclosed to you at the time of collection | Feature-specific functionality with explicit consent |
| Sensitive Personal Information | Precise geolocation; health data; any other sensitive data categories where permitted by law and necessary for a disclosed purpose | Feature-specific, with consent where required by law |
| Advertising & Attribution Data | Advertising identifiers (e.g., Google GAID), attribution event data, campaign IDs, conversion data, ad engagement signals | Ad measurement, offer attribution, fraud detection |
| Third-Party Partner Data | Conversion data, campaign data, device identifiers, completion status, payout data, anti-fraud signals received from advertising, attribution, analytics, offerwall, and survey partners | Rewards processing, fraud prevention, offer attribution |
If you are in the EEA, UK, or another jurisdiction requiring a legal basis, we rely on one or more of the following:
We may share personal data with the following categories of recipients:
We contractually require service providers not to use your personal data for their own independent purposes beyond what is permitted by contract and applicable law.
We do not sell personal data for money in the traditional sense. However, certain disclosures of identifiers, device information, advertising identifiers, usage data, precise location data, and similar data to advertising networks, attribution partners, analytics providers, monetization partners, and offerwall operators may constitute a "sale" under the broad definition used in California law (CCPA/CPRA) and certain other state laws. We treat those disclosures as "sales" for purposes of this Privacy Policy and your opt-out rights.
Yes. We do share personal data with third parties for cross-context behavioral advertising (i.e., targeted advertising). This includes sharing advertising identifiers, device identifiers, usage data, geolocation signals, and app activity data with advertising and attribution partners so they can serve ads targeted to your interests. Under California law, this constitutes "sharing" personal data. We disclose this to you transparently.
| Category of Personal Data | Sold? | Shared for Targeted Advertising? | Disclosed to Third Parties? |
|---|---|---|---|
| Advertising identifiers (GAID, etc.) | Possibly (broad definition) | Yes | Yes |
| Device identifiers | Possibly (broad definition) | Yes | Yes |
| IP address | Possibly (broad definition) | Yes | Yes |
| Usage and activity data | Possibly (broad definition) | Yes | Yes |
| Approximate location | Possibly (broad definition) | Yes | Yes |
| Installed apps data | Possibly (broad definition) | No | Yes (fraud prevention / attribution only) |
| Account / profile information | No | No | Service providers only |
| Contacts / SMS data | No | No | No (not shared with advertisers) |
| Health / sensitive information | No | No | No (unless you explicitly consent) |
You have the right to know:
You have the right to opt out of the sale of your personal data and the sharing of your personal data for targeted advertising purposes. This right applies to California residents (CCPA/CPRA), Colorado residents (CPA), Connecticut residents (CTDPA), Virginia residents (VCDPA), Utah residents (UCPA), and residents of other jurisdictions where such opt-out rights exist.
You may exercise your opt-out right using any of the following methods:
After you opt out, we will stop selling or sharing your personal data for targeted advertising within 15 business days of receiving a verifiable request. We may continue to disclose information to service providers where strictly necessary to operate, secure, and maintain the Services, detect fraud, process transactions, and comply with legal obligations.
We will not discriminate against you for exercising your opt-out rights.
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention periods may vary:
| Data Type | Retention Period |
|---|---|
| Account information | While your account is active + up to 3 years after closure |
| Transaction and reward records | Up to 7 years for accounting, fraud prevention, and audit |
| Support communications | Up to 3 years after resolution |
| Security logs and device identifiers | Up to 2 years for fraud detection and operational security |
| Advertising and analytics data | Up to 13 months or as required by partner agreements |
| Marketing data | Until you opt out or withdraw consent |
| Deletion request records | Minimal records to document compliance and prevent re-collection |
When we no longer need personal data, we delete, anonymize, or securely dispose of it in accordance with applicable law.
Depending on your jurisdiction, you may have the right to:
To exercise any right, contact us at:
We may verify your identity before processing your request. We will respond within the timeframe required by applicable law (typically 30–45 days).
If you are in the EEA, UK, South Africa, or another jurisdiction that provides this right, you have the right to lodge a complaint with your local data protection authority if you believe our processing of your personal data violates applicable law. In the UK, this is the Information Commissioner's Office (ICO). In the EEA, you may contact the supervisory authority in your country of residence.
We encourage you to contact us first so we can address your concern directly.
This section applies to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
See Section 5 above.
We may sell or share personal information (as defined under California law) as described in Section 8. California residents have the right to opt out — see Section 8.5.
California residents may have the following rights:
To submit a request: seon.geon@tecgames.org (Subject: "California Privacy Request").
Authorized agents may submit requests on your behalf with verifiable written authorization.
This section applies to Virginia residents under the Virginia Consumer Data Protection Act (VCDPA).
Virginia residents may have the following rights, subject to exceptions:
To exercise your Virginia rights, contact us at seon.geon@tecgames.org (Subject: "Virginia Privacy Request"). To appeal a denied request, use the same email with subject "Virginia Privacy Appeal."
Colorado residents may have rights under the Colorado Privacy Act including rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising and sale of personal data, and opt out of profiling. To exercise these rights, contact us at seon.geon@tecgames.org (Subject: "Colorado Privacy Request").
Connecticut residents may have rights under the Connecticut Data Privacy Act including rights to access, correct, delete, portability, opt out of targeted advertising, opt out of sale of personal data, and appeal denied requests. Contact us at seon.geon@tecgames.org (Subject: "Connecticut Privacy Request").
If GDPR, UK GDPR, or equivalent legislation applies to you, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and the right to withdraw consent (Art. 7(3)). You also have the right to lodge a complaint with a supervisory authority (Art. 77). Our lawful bases for processing are described in Section 6.
Where we rely on legitimate interests (Art. 6(1)(f)), you may object to processing. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
Contact our DPO at seon.geon@tecgames.org for GDPR-related requests.
If you are in Brazil, you may have rights under the Lei Geral de Proteção de Dados (LGPD), including rights to confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, revocation of consent, review of automated decisions, and the right to lodge a complaint with the ANPD. Contact us at seon.geon@tecgames.org.
If you are in South Korea, you may have rights under the Personal Information Protection Act (PIPA). You have the right to know whether your personal information is provided to or processed by third parties, to request access, correction, deletion, and suspension of processing, and to know whether your data is sold, shared, or entrusted to third parties. Contact us at seon.geon@tecgames.org.
The App may request the following device permissions, used only as described:
| Permission | Why It Is Requested | Is It Mandatory? |
|---|---|---|
| INTERNET | Core app connectivity, syncing, analytics, ads | Yes |
| Camera (pre-installed / system) | Scanning documents or capturing images for import; uses system camera only — no background access | No (only when you initiate a scan) |
| Location (approximate / precise) | Geolocation-dependent features, fraud prevention, offer eligibility | No (you may decline) |
| READ_CONTACTS | Referral features (only when you explicitly use the referral feature) | No |
| READ_SMS / RECEIVE_SMS | OTP / phone number verification (only for verification flows) | No |
| RECEIVE_BOOT_COMPLETED / notifications | Push notification delivery | No |
| READ_EXTERNAL_STORAGE (android:maxSdkVersion="28") |
Retained only for compatibility with Android 8 and below (SDK < 28).
On Android 9 (SDK 28) and above, the App uses the
Storage Access Framework (SAF) and the Photo and Video Picker,
which do not require this permission. We have set
android:maxSdkVersion="28" so this permission is not granted on
modern devices. No broad scanning of your storage occurs.
|
Legacy only (Android ≤ 8) |
| Photos & Videos access | The App uses the Android system Photo Picker (no broad media access required) | No |
You can manage and revoke most permissions at any time in your device's Settings → Apps → [App Name] → Permissions.
The App integrates third-party SDKs for analytics, advertising, attribution, crash reporting, fraud prevention, monetization, and similar functions. These SDKs may independently collect data from your device subject to their own privacy policies. We review and update this section when new SDKs are added.
| SDK Category | Purpose | May Collect |
|---|---|---|
| Analytics SDKs | App usage analytics, crash reporting, performance monitoring | Device ID, usage events, crash data |
| Advertising SDKs | Serving ads, ad targeting, frequency capping | Advertising ID, IP, usage signals |
| Attribution / MMP SDKs | Measuring campaign effectiveness, install attribution | Device ID, advertising ID, install events |
| Offerwall / Monetization SDKs | Delivering offer tasks, reward campaigns | Device ID, installed apps (where applicable), completion events |
| Anti-Fraud / Security SDKs | Detecting fraud, abuse, and bot activity | Device fingerprint, network info, behavioral signals |
| Support / Communication SDKs | In-app customer support chat | Account info, messages |
We only integrate SDKs that are up-to-date and have no known critical security issues. We do not use SDKs that have been flagged as "outdated" or having critical vulnerabilities. When new SDKs are detected in the App, we review their data collection practices and update this Privacy Policy accordingly.
Your personal data may be transferred to and processed in countries other than your country of residence, including the United Kingdom, the United States, and other countries where our service providers operate. Where required by law (e.g., GDPR), we implement appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or other lawful transfer mechanisms.
We implement reasonable technical, administrative, and organizational security measures — including encryption in transit and at rest — to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. We do not transmit personal data unencrypted. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your data has been compromised, contact us immediately.
The Services are not directed to children under 13 (or under 16 in the EEA/UK or such higher age as required by applicable law) unless expressly stated otherwise. We do not knowingly collect personal data from children below the applicable age threshold. We do not knowingly sell or share the personal data of children. If you believe a child has provided personal data to us, please contact us at seon.geon@tecgames.org and we will take prompt action to delete it.
The Services may contain links to third-party websites, offer providers, survey platforms, or partner services. Their privacy practices are governed by their own privacy policies. We are not responsible for third-party privacy practices and encourage you to review them before interacting with any third party.
You may request deletion of your account and associated personal data by:
We will process your deletion request within the timeframe required by applicable law. We may retain certain information after deletion where necessary for fraud prevention, legal compliance, tax/accounting obligations, dispute resolution, security, or enforcement of our agreements, as permitted by law.
We review and update this Privacy Policy at least annually and whenever there are material changes to our data practices — including the addition of new endpoints, SDKs, permissions, or data types. When we make material changes, we will post the updated version here and revise the "Last updated" date. For significant changes affecting your rights, we will provide additional notice (e.g., in-app notification or email) and, where required by law, obtain your consent.
For any questions, requests, or concerns about this Privacy Policy or our privacy practices:
Points4cash Ltd
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ, United Kingdom
Email: seon.geon@tecgames.org
Support: seon.geon@tecgames.org
We aim to respond to all privacy-related inquiries within 30 days of receipt.