Privacy Policy

Last updated: June 2026

1. Who we are

MBO Rewards ("MBO Rewards", "we", "us") operates mborewards.com and provides affiliate commerce infrastructure through a unified API. Our registered address is in India.

This Privacy Policy applies to data processed through our website (mborewards.com) and our API platform used by partner platforms ("Platforms"). End users of partner platforms ("Users") interact with MBO Rewards through their Platform, not directly.

2. Core privacy principle: Zero PII architecture

MBO Rewards is designed around a zero-PII principle. When Platforms integrate MBO Rewards, they pass an opaque, anonymised user token — not names, emails, or device identifiers. MBO Rewards cannot reverse-map attribution tokens to individual users.

This is an architectural constraint, not a policy choice. The system was built so that user identity data cannot enter our infrastructure.

3. Data we collect from website visitors

Contact form submissions: When you contact us via the website, we collect your name, email address, company name, and any message content. This is used solely to respond to your enquiry.

Analytics: We may collect anonymised usage data (pages visited, referrer, device type) to understand how the website is used. We do not use cookies for tracking across sessions. See our Cookie Policy for details.

Server logs: Standard web server logs (IP address, timestamp, request path) may be retained for up to 30 days for security and debugging purposes.

4. Data we process for partner platforms

API credentials: We store API keys in hashed form. Plaintext is shown once at creation and cannot be recovered.

Attribution tokens: Opaque tokens generated and passed by the Platform. These are stored in association with campaign IDs and conversion events. They cannot be linked to a user identity by MBO Rewards.

Click and conversion events: Timestamps, campaign IDs, attribution tokens, order values, and commission amounts. No user identifiers beyond the opaque token.

Commission and settlement data: Financial records required for monthly settlement processing. Retained for 7 years to meet tax and audit requirements.

5. Data residency and infrastructure

All MBO Rewards data is stored and processed on infrastructure located in India. We do not transfer personal data to servers outside India without appropriate safeguards.

Our infrastructure is designed to meet the data localisation and compliance requirements applicable to regulated financial institutions across our operating markets.

6. Security

All data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256. API keys are hashed server-side using bcrypt. We maintain immutable audit logs of all API calls and system events.

7. Data retention

Contact enquiries are retained for 12 months and then deleted. Attribution and conversion event data is retained for 24 months. Financial settlement records are retained for 7 years. Anonymised analytics data has no fixed retention limit.

8. Your rights

If you have submitted a contact form or are a named contact at a partner platform, you have rights to access, correct, or delete your personal data. To exercise these rights, email us at privacy@mborewards.com.

End users of partner platforms should direct privacy requests to their Platform, which is the data controller for their personal data. MBO Rewards acts as a data processor for Platform data.

9. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated to partner platforms with 30 days notice. The current version is always available at mborewards.com/privacy.

10. Contact

For privacy matters: privacy@mborewards.com

For general enquiries: mborewards.com/contact