Pre-launch notice
1. Who this notice covers
Redeem by Quest (“Redeem”, “we”, “us”) provides post-purchase reward and retention tools to participating venues. This notice covers venue owners and staff, customers using a Redeem QR or reward, people contacting us, and visitors to our website.
A participating venue may also decide why customer information is collected for its own business. Depending on the activity, Redeem and the venue may each have responsibilities for that information.
The final notice must name the operating legal entity, its registered contact details, and the exact controller and processor roles agreed with each venue.
2. Information we collect
- Customer name, phone number, and optional email address.
- Venue, visit time, reward, redemption, campaign, and staff-confirmation records.
- Purchase values when a venue or staff member chooses to record them.
- Venue contact details, campaign settings, staff names, and account identifiers.
- Google account details used to sign into a venue dashboard.
- A random, venue-scoped browser identifier stored in a cookie or browser storage to help detect repeated reward abuse and estimate unique menu visitors. Redeem stores only a one-way, venue-specific hash for menu analytics. It does not prove the identity of a physical device and cannot join activity between venues.
- Technical, security, and abuse-prevention records such as timestamps, PIN attempts, short-lived network and browser-family signals, session information, and error logs. Redeem does not store the raw network address in reward or approval-audit records.
- Venue-scoped pilot events such as scan starts, completed captures, validations, reward views, and redemptions. This event log does not copy names, phone numbers, or email addresses.
- Information included in a demo, pilot, support, email, or WhatsApp inquiry.
3. Why we use it
- To issue, validate, store, and redeem customer rewards.
- To operate venue dashboards, staff controls, reports, and customer reward history.
- To provide venues with privacy-conscious menu reach and activity reporting.
- To detect duplicate claims, fraud, misuse, and security incidents.
- To support venues and customers and improve product reliability.
- To send marketing only when a person has made a separate, optional choice to receive it.
- To comply with law, resolve disputes, and protect people, venues, Redeem, and Quest.
The proposed lawful basis depends on the activity and may include performing a requested service or contract, consent, documented legitimate interests such as security and product reliability, or a legal obligation. Counsel must approve the final lawful-basis record before live use. Reward delivery does not require consent to unrelated marketing.
4. Who can receive information
The venue where a customer used Redeem can receive information connected to that venue, including customer contact details, visit and reward records, and staff activity. A venue must not use that information outside agreed purposes or applicable law.
We also use service providers that help run authentication, databases, hosting, email delivery, analytics, security, and support. Current infrastructure includes Google Firebase and Google Cloud services, Vercel for web hosting, and Resend for eligible email delivery. We may disclose information to professional advisers, regulators, courts, or law-enforcement bodies when legally required.
We do not sell personal information.
5. Quest and cross-product use
Redeem and Quest share technical infrastructure. A Redeem customer does not automatically become an active Quest user merely because an identity exists in shared infrastructure. Joining Quest, receiving Quest marketing, or using Redeem data for a separate Quest experience should require a clear, optional choice.
6. Retention and international processing
Redeem must approve and implement a record-level retention and deletion schedule before collecting live customer data. The schedule must cover reward records, venue customer records, support messages, security logs, backups, and pilot events. The proposed approval-audit retention period is 180 days, enforced from a separate future expiry timestamp, while PIN-attempt buckets should expire after their short operational window. Automated deletion is not complete until the corresponding Firestore TTL policies are deployed.
Some service providers may process information outside Nigeria. Before live use, Redeem must document the countries, transfer ground, contracts, and other safeguards required by Nigerian data-protection law.
7. Your choices and rights
Subject to applicable law, you may ask to be informed about processing, access or correct information, object to certain processing, withdraw consent, request deletion or portability, and complain to the Nigeria Data Protection Commission. Direct-marketing consent can be withdrawn at any time, and withdrawing it does not cancel a valid reward.
Send a request to edwin@quests.group. We may need to verify your identity before acting on a request.
8. Security, children, and changes
We use access controls, signed and revocable sessions, server-side checks, transactional updates, scoped rate limits, and other measures designed to protect the service. No online system is perfectly secure. Redeem must also approve a written breach-response process before live use, including assessment, escalation, and legally required notifications.
Redeem is designed for adults and venue transactions, not for children to use independently. The pilot must not knowingly collect a child's information until counsel approves an age and parental-consent process. Contact us if you believe a child's information was submitted improperly.
We may update this notice as the product, providers, or law changes. The date at the top will show the latest revision.