Skip to content
RewardSpring

Legal

Privacy Policy

Last updated July 16, 2026

This Privacy Policy explains how RewardSpring collects, uses, shares, and protects personal information in connection with our software-as-a-service platform (the “Service”), which helps SaaS founders run affiliate-commission and customer-referral reward programs. It applies to our marketing website at getrewardspring.com, the founder application, and the branded referral portals we host on behalf of our customers.

Who we are

RewardSpring is operated by Fapbric Technology Solutions, LLC (“RewardSpring,” “we,” “us,” or “our”) and provides the Service to businesses (“founders” or “customers”). For privacy questions, contact us at hello@getrewardspring.com.

Our roles: controller and processor

Our role under data-protection laws such as the EU and UK General Data Protection Regulation (“GDPR”) depends on whose data we handle:

  • Founder account data — we are a controller. When a founder signs up for, pays for, and administers the Service, we determine how and why their account and usage information is processed. This Privacy Policy governs that data.
  • Founders’ partner and customer data — we are a processor / service provider. When a founder runs a program, we process the personal data of their affiliates, partners, and customers on the founder’s behalf and under their instructions. The founder is the controller of that data and is responsible for its collection and for the privacy notices provided to those individuals. If you are an affiliate, partner, or customer of a founder, please direct privacy requests to that founder; we will assist them in responding.

Information we collect

  • Account data: your name, email address, and authentication details (for example, passkey, magic link, or one-time code metadata) used to access and secure the founder app.
  • Billing data: your subscription plan and billing status. Card payments for your RewardSpring subscription are processed by Stripe; we do not store full card numbers.
  • Connected Stripe data: connected-account identifiers and subscription, conversion, and payment events read through Stripe Connect to calculate conversions and rewards. We connect using OAuth and do not ask you to paste Stripe secret keys.
  • Program data: information about affiliates, partners, and customers, including names, email addresses, payout email addresses, referral links, clicks, signups, conversions, and reward and commission records.
  • Fraud signals: where possible, we hash IP addresses and user-agent strings to detect self-referrals and abuse rather than storing raw identifiers unnecessarily.
  • Usage and log data: device, browser, and diagnostic logs needed to operate, troubleshoot, and secure the Service.
  • Product analytics: privacy-friendly, consent-gated analytics about how the app and site are used (see Cookies and analytics below).

Sources of information

We collect information directly from founders when they register and use the Service; from the founder’s connected Stripe account through Stripe Connect; and automatically through logs and consent-gated analytics. For program data, we receive information from the founder and from the activity of their affiliates, partners, and customers.

How we use information and our legal bases

Where the GDPR applies, we rely on the following legal bases under Article 6:

  • Performance of a contract (Art. 6(1)(b)): to create and administer accounts, connect Stripe, track referrals, attribute conversions to the correct referrer, calculate pending, approved, and paid commissions and rewards, and provide support.
  • Legitimate interests (Art. 6(1)(f)): to operate, secure, and improve the Service, prevent fraud and abuse, and communicate about the Service, balanced against your rights and interests.
  • Consent (Art. 6(1)(a)): for non-essential product analytics and any optional communications, where required. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): to meet accounting, tax, and other legal requirements.

When we process program data as a processor, we do so only to provide the Service and on the documented instructions of the founder who acts as controller.

Subprocessors

We use a small set of trusted subprocessors to run the Service. Each is bound by contractual confidentiality and data-protection obligations and processes data only as needed to provide their function:

  • Stripe — payment processing and Stripe Connect for reading billing and conversion data.
  • Amazon SES — sending transactional and notification email.
  • Supabase — managed Postgres database and application hosting.
  • Cloudflare — CDN, custom-domain routing, and SSL certificate management.

A current list of subprocessors is available on request from hello@getrewardspring.com. Where required, we will provide advance notice of new subprocessors so that customers with a Data Processing Addendum can exercise any right to object.

Data sharing and disclosure

We do not sell personal information. We share personal information only with the subprocessors listed above; with a founder in connection with their own program (for program data); where you direct us to; to comply with law, legal process, or lawful requests; to protect the rights, safety, and security of RewardSpring, our customers, or the public; and in connection with a merger, acquisition, or sale of assets, in which case we will notify affected customers and any successor will remain bound by this Policy.

International data transfers

RewardSpring and several of our subprocessors are located in or process data in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States and other countries. Where we transfer personal data subject to the GDPR out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum), together with supplementary measures where needed.

Data retention

We retain personal information for as long as your account is active or as needed to provide the Service, and thereafter only as necessary to comply with legal, accounting, tax, and dispute-resolution obligations, to enforce our agreements, and to maintain security. When data is no longer needed, we delete or anonymize it. When we act as a processor, we retain and delete program data in accordance with the founder’s instructions and our Data Processing Addendum.

Security

We use technical and organizational measures to protect personal information, including encryption in transit and at rest, least-privilege access controls, and tenant isolation. For details, see our Security page. No method of transmission or storage is completely secure, but we work continuously to protect your data.

Your rights (GDPR)

If you are in the EEA, the UK, or Switzerland, you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, and the right to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority. To exercise these rights for data we control, email hello@getrewardspring.com. If your request concerns program data controlled by a founder, we will refer you to, or assist, that founder.

Your rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, the right to access and delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the “sale” or “sharing” of personal information. RewardSpring does not sell personal information and does not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights. To make a request, email hello@getrewardspring.com; we will verify your request before responding, and you may use an authorized agent as permitted by law.

Cookies and analytics

We use strictly necessary cookies to operate the Service (for example, to maintain authenticated sessions). We use privacy-friendly, consent-gated product analytics to understand how the app and site are used and to improve them. We do not use advertising cookies and do not engage in cross-site advertising tracking. Where required, analytics run only after you consent, and you can decline or withdraw consent at any time.

Children’s privacy

The Service is a business tool that is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

Data breach notification

We maintain an incident-response process. In the event of a personal-data breach, we will notify affected customers and, where required, regulators and data subjects, without undue delay and in accordance with applicable law. When we act as a processor, we will notify the relevant founder so they can meet their own notification obligations.

Data Processing Addendum

For customers who require one, a Data Processing Addendum (DPA) incorporating the Standard Contractual Clauses is available. Request a copy at hello@getrewardspring.com.

Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

Contact

Privacy questions or requests? Email hello@getrewardspring.com.