RewardsMate legal

Security

Last updated: 1 August 2026

This page explains the security practices RewardsMate aims to follow. It does not claim certifications or controls that have not been independently verified.

1. Account authentication

Customer accounts use authentication controls such as one-time codes or supported sign-in methods. Keep your device and account credentials secure.

2. Role-based retailer access

Retailer staff access to Shopper's Mate tools is intended to be role-based so team members only see information needed for their role at their own business.

3. Encryption in transit

RewardsMate website and app traffic is intended to use HTTPS/TLS encryption in transit.

4. Secure service-provider usage

We use reputable service providers for hosting and related services and expect them to apply appropriate security controls for the services they provide.

5. Access controls

Internal access to customer and retailer data is limited to people who need it to operate, support or improve the product.

6. Audit logging

Where implemented, system activity may be logged to support troubleshooting, fraud review and operational oversight.

7. Fraud monitoring

We may review unusual account, points or redemption activity to help protect customers, retailers and the network.

8. Responsible vulnerability reporting

If you believe you have found a security vulnerability, email support with a clear description and steps to reproduce. Do not access data that is not yours or disrupt the service.

9. Lost-device guidance

If your phone is lost or stolen, use your device-provider tools to lock or erase the device where possible, and contact RewardsMate support so we can help secure your account.

10. Support contact

For security or account concerns, use the Support page pathways. Support