Privacy Notice
Effective and last updated: September 28, 2026. This notice explains what CV Management Solutions, LLC, operator of Repass (“we,” “us”), collects, how it's used, and how it's protected.
1. Scope of this notice
This notice covers Repass's dashboard (used by business owners) and the wallet-pass sign-up and check-in pages used by their customers. It does not cover the point-of-sale systems you connect (Square, Clover, etc.) or Apple/Google's own Wallet apps, which have their own privacy practices.
2. Information we collect
From business owners: your name, email, business name, branding assets you upload, reward rules, and billing information (processed directly by Stripe — Repass does not store your card number).
From your customers, on your behalf: first and last name, email address, phone number, and points balance, collected when they sign up for your loyalty program or when you add them manually or import them from a connected point-of-sale system.
Automatically: only what's needed to keep you signed in (an authentication session). Repass does not currently use analytics or advertising tracking cookies, and does not run any session-recording or screen-recording tool on its site.
3. How we use this information
- To operate the loyalty program you configure — issuing and updating wallet passes;
- To send transactional email (a wallet-card link, a receipt) via our email provider, Resend;
- To process your subscription payment via Stripe;
- To award a point automatically when you connect a supported point-of-sale system; and
- To provide customer support and maintain the security of the service.
We do not sell customer data, and we do not use it for advertising.
4. Where this information lives
Customer and account data is stored in our database, hosted by Supabase. Depending on which features you use, data also passes through: Stripe (billing), WalletWallet (wallet pass generation), Resend (transactional email), Vercel (hosting), and, if connected, Square, Clover, and/or your own Stripe account. Each of these providers processes data only as needed to provide their part of the service to us.
5. Payment and point-of-sale integrations
If you connect Square, Clover, or your own Stripe account, Repass reads only whether a sale completed and the contact information (phone or email) tied to that sale, in order to match it to one of your enrolled customers and award a point. Repass never requests or stores card numbers, CVV codes, bank account details, or itemized purchase contents from any of these integrations.
A connected Stripe account is granted read-only access and is separate from the Stripe billing used for your Repass subscription. Repass stores no Stripe credentials for it — only the account identifier — and you can revoke the connection at any time.
6. Data retention
Customer records are retained for as long as your account is active. Removing a customer from your dashboard marks their record as removed and revokes their wallet pass; it does not immediately erase their historical point-activity records, which are kept for your own program's recordkeeping. You can request permanent deletion of a specific customer's data by contacting us at the address below.
7. Your rights and choices
Business owners can access, correct, or delete their account information directly from the dashboard. If you are a business owner's customer and want to access, correct, or request deletion of your information, contact the business whose program you joined, or reach us directly at the email below and we will forward your request.
8. Security
Point-of-sale access tokens are encrypted at rest (AES-256-GCM). Access to a business's data is restricted to that business's own account via database-level row security. All traffic to Repass is encrypted in transit (HTTPS). See our published security practices for full detail.
9. AI tools used to build and operate Repass
Repass is built and maintained with the help of Anthropic's Claude, an AI coding assistant. Claude is used during development and maintenance of the Repass codebase and does not have standing access to production customer data as part of that process.
10. Children's privacy
Repass is intended for use by business owners aged 18 and older. It is not directed at children, and we do not knowingly collect information from children under 13.
11. Changes to this notice
We may update this notice from time to time. We will update the “last updated” date above, and for material changes, notify active business-owner subscribers by email.
12. Contact
Questions about this notice, or a data access/deletion request, can be sent to cuadventuresllc@gmail.com.