Privacy Policy
Effective date: August 6, 2026 Last updated: August 6, 2026
1. Who we are
Steward Technologies, Inc. ("Steward," "we," "us," "our") operates the Steward iOS application (the "App"), which helps you decide which of your credit cards to use based on nearby merchants, your spending profile, and loyalty memberships.
Contact: [email protected]
2. What this policy covers
This policy describes the personal information the App collects, how we use it, who we share it with, and the choices you have. It covers the mobile app and our backend services.
It does NOT cover:
- Websites, products, or services operated by third parties we link to (mapping services, issuer websites, and similar)
- Actions you take inside your credit card issuer's own app or website
3. Information we collect
3.1 Information you provide
- Account information you provide when signing in, which may include your name and email address
- Preferences you set in the App (such as reward priorities and notification settings)
- Card and program information you enter, meaning the credit cards and loyalty programs you tell us you hold. We do NOT access your actual card numbers, statements, balances, or transaction data.
- Content you create in the App (such as goals, saved lists, and similar user-generated inputs)
- Community reports you submit to help improve the App's accuracy
3.2 Information collected automatically
- Location data — precise location (via Apple Core Location, with your permission) to power location-based features. You can grant "While Using" or "Always" access, or deny the App location entirely. Denying location removes proximity-based features.
- Device and app information — iOS version, app version, device model, language, time zone
- Usage analytics — which screens you view, which features you use, and how long sessions last, processed by an analytics service provider under contract
- Crash and performance diagnostics — when the App crashes, encounters an error, or a feature is slow, we send a diagnostic event to an error monitoring provider under contract. These events include the error message, a stack trace, the device model and iOS version, the App version, and (for the purpose of correlating crashes across a user's sessions) your IP address and a device identifier. We do not send the contents of your card list, loyalty memberships, preferences, or any financial data to the error monitoring provider.
3.3 Information we do NOT collect
- Your credit card numbers, PINs, expiration dates, or security codes
- Transaction history from your credit card accounts
- Your credit score or credit report data
- Contacts, photos, calendar, microphone, or camera (unless a feature clearly asks permission in a future version)
4. How we use information
- Provide the App's core recommendation and lookup features
- Sync your profile across devices
- Debug problems, measure feature adoption, and improve the App
- Send you notifications about relevant recommendations or updates, if you have enabled them
- Communicate with you about the App (support, service updates)
5. Who we share information with
We share limited information with a small set of service providers under contract, in the following categories:
| Category | What's shared | Why |
|---|---|---|
| Identity provider (Sign in with Apple) | Your Apple-provided user identifier and optional email/name | Authentication |
| Mapping and places provider | Your approximate location at time of a location-based query | To look up nearby merchants and places |
| Hosting and infrastructure provider | Data processed by our backend | Hosting our API and database |
| Analytics provider | Usage events, device info | Product analytics |
| Error monitoring provider | Crash reports, performance traces, IP address, device identifier | Debugging crashes and performance issues |
A current list of specific sub-processors is available on request by emailing [email protected].
We do NOT sell your personal information. We do NOT share your information with advertisers or data brokers. We do NOT share it with credit card issuers.
We may disclose information if required by law, subpoena, or court order, or to protect the safety or rights of Steward, our users, or the public.
6. Data retention
- Profile data, card lists, trips, and loyalty data: retained while your account is active. Deleted within 30 days when you delete your account (in-app) or email us a deletion request.
- Location data: not stored long-term on our servers — used only to answer the immediate merchant-search query. Cached by Apple on your device per iOS standards.
- Analytics events: retained by PostHog for up to 7 years.
- Crash and performance events: retained by Sentry for 90 days on default plans, after which they are automatically deleted.
- Server logs: rotated every 30 days.
7. Your rights and choices
You can:
- Revoke location permission at any time in iOS Settings → Privacy & Security → Location Services → Steward.
- Revoke notification permission in iOS Settings → Notifications → Steward.
- Disable analytics — tell us and we'll opt out your device ID from PostHog collection. (A self-serve toggle is on our post-launch roadmap.)
- Request a copy of your data — email [email protected].
- Delete your account in-app — open the App → Settings → Account → Delete Account. This permanently deletes your profile, cards, trips, and loyalty data from our servers. You can also email [email protected] with the email tied to your Apple Sign-In and we will delete your data within 30 days.
- Revoke Sign in with Apple — iOS Settings → Apple ID → Password & Security → Apps Using Your Apple ID.
California residents (CCPA/CPRA)
You have the right to know, delete, correct, and limit the use of your personal information. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
EU/UK residents (GDPR/UK GDPR)
The legal bases we rely on are (a) your consent (for analytics and location), (b) performance of our contract with you (providing the App's features), and (c) legitimate interest in improving the App. You have rights of access, rectification, erasure, restriction, portability, and objection. Contact [email protected].
8. Children
Steward is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact [email protected] and we will delete it.
9. Security
We encrypt data in transit using HTTPS/TLS. Our database is operated by a third-party hosting provider with provider-managed backups. Your Apple identifier is stored on our servers. Authentication tokens are stored in the iOS Keychain on your device. No system is perfectly secure, but we use standard industry practices and commit to disclosing breaches to affected users as required by applicable law.
10. Third-party links and data
The App may link out to issuer websites or mapping services. Those services have their own privacy policies. This policy does not cover them.
11. Beta and pre-release versions
During the initial TestFlight beta, the App may log additional diagnostic information to help us identify and fix issues. This information is used only to improve the App, is not shared with advertisers, and is deleted on the same cadence as our regular logs.
12. Changes to this policy
We may update this policy as the App evolves. Material changes will be announced in-app or via email. The "Effective date" at the top reflects the latest version.
13. Contact
Steward Technologies, Inc. [email protected]