Rewordin
  • Features
    ⚡ Bulk Gift Card API🔌 HRIS Integrations🌍 Global Rewards🎁 Reward Marketplace📊 Analytics & ReportingView all features →
  • Use Cases
    💰 Sales Teams📣 Marketing Teams🤝 Channel Partners👥 HR & People Ops⚙️ Engineering Teams🎧 Customer Support📊 Finance & AccountingView all use cases →
  • Resources
    🎁 Employee Rewards👏 Employee Recognition📈 Employee Engagement🏭 Industries🏆 Customers📝 Blog💰 Pricing🏢 About Us🧮 ROI Calculator
FeaturesBulk Gift Card API NewUse CasesEmployee RewardsEmployee RecognitionEmployee EngagementIndustriesBlogAboutROI CalculatorPricing
Log In
RewordinREWORDIN

The global employee rewards platform. Recognize, reward, and retain your best talent worldwide.

Platform

FeaturesBulk Gift Card APIHow It WorksIntegrationsPricingSecurityAll Use Cases

Solutions

HR & People OpsSales TeamsEngineering TeamsMarketing TeamsCustomer SupportFinance & AccountingChannel Partners

Resources

Employee RewardsEmployee RecognitionEmployee EngagementIndustriesROI CalculatorBlogRecognition Software 2026Tax-Free Gifts PolandROI of RecognitionRewards Program GuideHRIS Integration Guide

Company

AboutCustomers
hello@rewordin.com
Wrocław, Poland

Get the latest insights on employee rewards.

Secure Payment Methods

Visa
Mastercard
American Express
PayPal
Apple Pay
Google Pay
Samsung Pay
Stripe
Klarna
Amazon Pay
Shop Pay
Square
Discover
Maestro
UnionPay
Alipay
Bitcoin
Ethereum
BitPay
MetaMask
Cash App
Skrill
Payoneer
Western Union
MoneyGram
Gumroad

And 100+ more payment methods available worldwide

© 2026 Rewordin. All rights reserved.

Privacy PolicyTerms of ServiceSecurity

Book a Demo

We'll contact you within 24 hours to schedule your demo

🔒 Legal · Privacy

Privacy Policy

This policy explains how Rewordin collects, uses, discloses, and safeguards your information when you use our global employee rewards and recognition platform. We are committed to protecting your privacy and being transparent about our data practices.

Effective Date
June 9, 2026
Last Updated
June 9, 2026
Version
3.2
Last Reviewed
External counsel
On this page
  1. Information We Collect
  2. How We Use Your Information
  3. Legal Basis for Processing
  4. Data Security
  5. International Data Transfers
  6. Data Retention
  7. Your Rights
  8. Cookies & Tracking
  9. Third-Party Services
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us
Jump to section
  1. Information We Collect
  2. How We Use Your Information
  3. Legal Basis for Processing
  4. Data Security
  5. International Data Transfers
  6. Data Retention
  7. Your Rights
  8. Cookies & Tracking
  9. Third-Party Services
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us

At Rewordin (“we”, “our”, or “us”), we are committed to protecting your privacy and ensuring the security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our global employee rewards and recognition platform, available at rewordin.com and through our integrations.

This policy applies to all Rewordin customers, end-users (employees who receive rewards), and visitors of our website. By using Rewordin, you agree to the practices described below.

1. Information We Collect

We collect four categories of information. Each is handled according to the legal basis described in Section 3.

👤 Account & Workspace Data

Information you provide when creating and configuring a Rewordin account.

  • Full name, work email, job title
  • Company name, size, industry, country
  • Preferred currency, time zone, language
  • Password (hashed, never stored in plain text)

🔌 HRIS & Integration Data

Data synced from systems you connect (Workday, BambooHR, SAP, Personio, ADP, etc.).

  • Employee names, emails, departments
  • Employment dates, manager hierarchy
  • Custom fields you choose to map

🎁 Reward & Transaction Data

Data generated as you use the recognition and rewards features.

  • Reward types, amounts, recipients, senders
  • Delivery status and redemption events
  • Budget allocations, approval workflows
  • Tax classification data for compliance

📊 Usage Data

Automatically collected information about how you interact with Rewordin.

  • Pages visited, features used
  • Log data: IP address, browser, device
  • Aggregated analytics (no personal targeting)

2. How We Use Your Information

We use the collected information to:

  • Deliver, fulfil, and track employee rewards across 150+ countries
  • Process reward transactions and manage multi-currency conversions
  • Generate tax-compliance reports (1099, P11D, VAT, and other regional forms)
  • Sync employee data with your connected HRIS and collaboration platforms
  • Send reward notifications and service-related communications
  • Provide customer support and resolve issues
  • Detect and prevent fraud, abuse, and security incidents
  • Improve our platform through aggregated, anonymized analytics
  • Comply with legal and regulatory obligations

3. Legal Basis for Processing (GDPR)

Under the EU General Data Protection Regulation, we process your personal data on the following legal bases:

  • Contract performance — to deliver the service you signed up for
  • Legitimate interests — to secure the platform, prevent fraud, and improve it
  • Legal obligation — to meet tax, accounting, and regulatory requirements
  • Consent — for analytics cookies, marketing communications, and optional features

4. Data Security

We implement enterprise-grade security controls to protect your data, organized around the principle of defense in depth:

  • Encryption: TLS 1.3 in transit; AES-256 at rest
  • Infrastructure: Hosted on SOC 2 Type II aligned cloud providers
  • Access controls: Role-based access control (RBAC), SSO/SAML, multi-factor authentication
  • Payment handling: All payment data handled by PCI-DSS compliant payment processors and gift card suppliers; Rewordin does not store payment card numbers on our infrastructure
  • Data isolation: Each organisation’s data is logically isolated in a multi-tenant architecture; no customer can access another customer’s data
  • Audit logging: All administrative and data-access actions are logged and retained for compliance review
  • Penetration testing: Annual third-party security assessments and continuous vulnerability scanning
  • Incident response: Documented breach-notification process aligned with GDPR’s 72-hour requirement

5. International Data Transfers

Rewordin is headquartered in Wrocław, Poland, in the European Union. Your data is primarily processed and stored within the EU. When a reward delivery requires sharing limited information (such as a recipient email address) with a supplier or processor outside the EU, we ensure appropriate safeguards are in place, including:

  • European Commission Standard Contractual Clauses (SCCs)
  • EU-U.S. Data Privacy Framework certification, where applicable
  • Adequacy decisions for transfers to whitelisted jurisdictions
  • Encryption in transit and at rest for all cross-border transfers

A copy of our current transfer safeguards is available on request to dpo@rewordin.com.

6. Data Retention

We retain personal data for as long as needed to provide the service and meet our legal obligations:

  • Account data: While your account is active, plus 30 days after deletion for recovery
  • Reward transaction records: 7 years from transaction date (required by most tax authorities)
  • Audit logs: 2 years from the action date
  • Tax reports: 10 years where local law requires (e.g., Poland’s 5-year retention plus buffer)
  • Backups: 90 days rolling, after which they are deleted automatically

You may request deletion of your account and data at any time. We will remove your data within 30 days, except where retention is required by law (e.g., tax records).

7. Your Rights

Under the GDPR, UK GDPR, CCPA, and other applicable data protection laws, you have the right to:

Access the personal data we hold about you
Correct inaccurate or incomplete data
Delete your data (the “right to be forgotten”)
Restrict or object to specific processing activities
Portability — receive your data in a structured, machine-readable format (CSV or JSON)
Withdraw consent at any time, without affecting prior processing
Lodge a complaint with your local data protection authority
Object to automated decision-making including profiling

To exercise any of these rights, email dpo@rewordin.com. We respond within 30 days at no cost. EU residents may also contact the Polish Data Protection Authority (UODO) at uodo.gov.pl.

8. Cookies & Tracking

We use a small number of cookies, classed into three categories:

  • Essential cookies — required for authentication, security, and the site to function. Cannot be disabled.
  • Analytics cookies — PostHog, set only after consent. Used to understand aggregate usage patterns; no personal targeting, no data sold to third parties.
  • Marketing cookies — not currently used on rewordin.com. We do not run third-party advertising trackers on this site.

You can manage cookie preferences in your browser settings or through the cookie banner on your first visit.

9. Third-Party Services

We work with a small number of vetted sub-processors to deliver the service. The full current list, with the data they process and where they are based, is available at /privacy/sub-processors on request. All sub-processors are bound by data processing agreements aligned with GDPR Article 28.

Common categories of sub-processor include:

  • Cloud infrastructure providers (hosting, database, storage)
  • Gift card and reward suppliers (fulfilment, redemption)
  • Payment processors (PCI-DSS compliant)
  • Email and notification providers (transactional email)
  • Analytics tools (only with consent)

10. Children’s Privacy

Our services are intended for business use by adult employees and contractors. We do not knowingly collect personal information from anyone under 16, or under 13 with verifiable parental consent where local law requires. If you believe we have collected information from a minor in error, contact dpo@rewordin.com and we will delete it within 7 days.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and “Last Updated” date at the top of this page indicate the current revision. For material changes (changes that affect your rights or how we process your data), we will notify you at least 30 days in advance by email and by a banner in the platform.

Previous versions are archived and available on request.

12. Contact Us

For any questions about this Privacy Policy, to exercise your data rights, or to contact our Data Protection Officer:

Contact & Data Protection Officer

Email
dpo@rewordin.com
General
hello@rewordin.com
Postal
Rewordin
Wrocław, Poland

You may also review our Terms of Service for additional information about using the Rewordin platform.