Privacy Policy

Last updated August 25, 2026

CC Reward (cc-reward.com) helps you track your credit cards' perks, credits, and rewards. This policy says plainly what we collect, why, and what we never do with it.

What we collect

  • Account basics — your name, email, and a password hash (or your Google account link if you sign in with Google), plus two-factor authentication settings.
  • Your card portfolio — which card products you tell us you hold, when you opened or closed them, nicknames, spend-purpose tags, and the perk usage you log (including one-off claims like purchase protection). We never ask for or store card numbers.
  • Bank transaction data, only if you connect it — if you link a bank through Plaid (or another read-only aggregator you explicitly connect), we receive read-only transaction history (date, amount, merchant, category) for the accounts you approve. We never see or store your bank credentials; the aggregator handles authentication with your bank directly. Linking is optional and every connection can be removed in Settings, which deletes the transactions we hold.
  • Your preferences — the answers you give inside the product, like which credits you'd realistically use, which included perks matter to you, notification settings, and dismissed banners. These exist purely to make your own numbers and alerts accurate.
  • Confirmed merchant mappings — when you confirm a detected recurring charge as a known service from our catalog, we keep the billing-descriptor-to-service mapping (with its typical price and billing period) so the same biller can be recognized for other users. This never includes who confirmed it, your custom names, or any of your transactions — and other users only ever see it as a suggestion on a charge already sitting in their own account.
  • Household sharing — if you join a household, the other members see the shared wallet: cards, perk states, and (if connected) transactions on household cards. That's the product working as intended — only join a household with people you trust.
  • Questions you ask — when you use Ask, we keep the text of your question along with your account id and when you asked, so we can see how the feature is used and control costs. Question history is kept for up to 24 months and is visible to site administrators; if you delete your account, your questions are detached from you immediately.

How we use it

To run the product for you: generating perk windows and expiry reminders, computing fee-versus-value math, estimating points earned, matching transactions to credits, and drawing your household's graph.

Two features send data to an AI inference provider. Merchant categorizationsends descriptors only (like "DOORDASH 855-431") — never your name, balances, or account identifiers. Ask, when you use it, additionally sends the question you typed together with the wallet context needed to answer it: your card names and nicknames, spend-purpose tags, annual fees, and which credits you still have unused. It does not send your transactions, your email, or your name. If you would rather not send that, simply don't use Ask — nothing else on the site uses it.

Where the card facts come from

The card catalog itself — fees, credits, welcome offers, official terms — is built from issuers' own published pages, public regulatory filings (the CFPB credit card agreement database), and licensed card-data providers. None of that involves your data, and every catalog fact shows its origin in the product. Our developer API, where enabled, serves only this catalog data — never anything about you or your household.

What we never do

  • We do not sell your personal information, and we do not share it with advertisers.
  • We do not store card numbers (PANs) or bank login credentials — ever.
  • We do not move money. All bank access is read-only.
  • We do not use your data for anything you haven't seen in the product.

How it's protected

Everything is encrypted in transit (TLS) and at rest. Bank access tokens and two-factor secrets are additionally encrypted at the application layer before touching the database. Two-factor authentication is mandatory for password accounts. Access to production systems is limited and protected by MFA.

Service providers

We use a small set of processors to run the service: Vercel (hosting), Neon (database), Cloudflare (network protection and file storage), Plaid (bank connections you authorize), Resend (email), Google (optional sign-in, bot protection, and the icon font and vendor logos your browser loads), and an AI inference provider (merchant categorization and the Ask feature, as described above). Each receives only what its job requires.

Your controls

  • Disconnect any bank in Settings — its transactions are deleted immediately.
  • Remove cards, perks, or logged history anytime.
  • Delete your account yourself in Settings (bottom of the General tab) — or email [email protected] — deletion is permanent, completed within 30 days, and revokes our access at Plaid for any bank you had connected.

Changes & contact

If this policy changes materially, we'll note it in the in-product changelog and update the date above. Questions: [email protected]. Security concerns: [email protected].