Privacy Policy
What we collect when you use the Store, what we do with it, who we share it with and the choices you have.
Last updated: 7 October 2026. Operated by Touchstone Enterprises Private Limited ("OffiNeeds"), 3, 1st Floor, Old Mangammanapalya Road, Bandepalya, Garvebhavi Palya, Bommanahalli, Bengaluru, Karnataka 560068, India. Questions: rewards@offineeds.com.
1. Who is responsible
Touchstone Enterprises Private Limited, Bengaluru, India ("OffiNeeds") operates rewards.offineeds.com and is the data fiduciary (controller) for the personal data described here. For data about members of a rewards programme, the programme sponsor (normally your employer) decides who receives points; OffiNeeds processes your data to run the Store and deliver vouchers.
2. What we collect
- Account: name, email address, password (stored as a one-way hash), the country you select and, for Business Rewards, your organisation name, country, tax ID and role.
- Verification: the email address or Indian mobile number you confirm with a one-time code before certain orders. The mobile number is kept on the order so the voucher partner can deliver and support the voucher.
- Orders and wallet: points credited and spent, coupon codes used, orders placed, the vouchers issued to you (codes are stored encrypted) and your redemption history.
- Technical: IP address, country derived from it, browser and device type, pages visited and timestamps, collected in server logs and by our security providers to keep the Store running and safe.
- Support: what you write to us and our replies.
We do not collect card or bank details from members. Business Rewards payments are taken by Razorpay on its own pages; we receive only the payment reference and status.
3. Why we use it
- To run your account and wallet, credit points sent by your sponsor, and deliver and support vouchers (performance of our contract with you).
- To tell your sponsor whether the points it funded were redeemed. A sponsor sees redemption status and totals per person for its own programme; it does not see your voucher codes.
- To send transactional emails: voucher delivery, balance updates, one-time codes, password resets and order problems. We do not send marketing email from the Store.
- To prevent fraud, abuse and attacks, and to meet legal and tax obligations (legitimate interest and legal duty).
- To improve the Store using aggregated, non-identifying statistics.
4. Who we share it with
- Voucher partners: authorised gift card distributors in India and other countries receive the brand, amount, your email and, for Indian brands, your mobile number, so the voucher can be issued and supported. They act on our instructions for issuance; for the voucher itself, the brand's own privacy terms apply once you use it.
- Your programme sponsor: redemption status and amounts for points it funded, as described above.
- Service providers: email delivery (Twilio SendGrid), payment processing for business top-ups (Razorpay), content delivery and security (Cloudflare), and hosting. They process data only to provide those services.
- Authorities: where the law requires, or to protect the Store, its users or others.
We do not sell personal data.
5. Where it is stored and transfers
The Store and its database are hosted in India. Email delivery, security and some voucher partners operate from other countries, so limited data (for example your email address and the voucher order) is transferred to them to perform the service. We use providers with appropriate contractual safeguards. If you are outside India, your data is processed in India under this policy.
6. How long we keep it
Account and wallet data are kept while your account exists and for as long as the sponsor's programme requires. Order and voucher records are kept for 8 years to meet Indian tax and accounting rules and to support voucher disputes. Server and security logs are kept for up to 12 months. Support correspondence is kept for 3 years. After these periods data is deleted or anonymised.
7. Your rights
Under the Digital Personal Data Protection Act, 2023 (India) and, where it applies to you, other privacy laws such as the GDPR, you can ask us to:
- tell you what personal data we hold about you and provide a copy;
- correct or complete it;
- delete it, where we no longer need to keep it (some order records must be retained by law);
- nominate someone to exercise these rights for you;
- raise a grievance about how your data is handled.
Write to rewards@offineeds.com from the email address on your account. We respond within 30 days. Our Grievance Officer is the Chief Technology Officer, Touchstone Enterprises Private Limited, reachable at the same address. If you are not satisfied, you may approach the Data Protection Board of India or your local supervisory authority.
8. Cookies
The Store uses only the cookies it needs to work: a session cookie that keeps you signed in, a cookie that remembers the country you selected, and security cookies set by Cloudflare to protect against automated attacks. We do not use advertising or tracking cookies. Blocking these cookies stops the Store from working.
9. Security
All traffic is encrypted (HTTPS). Passwords are hashed, voucher codes are stored encrypted, the database is encrypted at rest, and access to production systems is limited to named staff on a need-to-know basis with audit logging. No system is perfectly secure; if we learn of a breach that affects you we will notify you and the authorities as the law requires.
10. Children
The Store is for adults in a rewards programme. We do not knowingly collect data from children under 18.
11. Changes
We may update this policy; the date at the top shows the current version. Material changes are announced in the Store.