Privacy Policy
Version 3.3 | Last Updated: August 2, 2026
1. Scope; Controller
This Privacy Policy (this "Policy") describes how Cashout Mobile LLC, an Ohio limited liability company with its principal place of business in Columbus, Ohio, USA ("Cashout," "we," "us"), collects, uses, discloses, and retains personal information in connection with the Cashout iOS application, the Cashout merchant web portal, and the website at cashoutmobile.com (collectively, the "Service"). Cashout is the controller of the personal information described in this Policy, except for merchant personnel data as described in Section 7, for which the inviting merchant is the controller.
2. Categories of Personal Information Collected
- Account information. Student users register with a school email address and password. Business users register with a business name, contact email address, and password.
- Minimum-age eligibility. Student users enter their age during onboarding. The application evaluates that entry on the user's device; Cashout does not transmit or store the exact age or a birth date. Cashout records only whether the student met the Service's minimum age and the threshold applied.
- Student profile and optional demographics. Students select a pseudonymous nickname and avatar and may consent to provide class year, gender, major, and organizational affiliation. Optional demographics are stored separately and may be withdrawn.
- Contacts. If a user permits contact matching, the application normalizes and cryptographically hashes email addresses and phone numbers on the device. Raw address-book entries are not uploaded. The resulting hashes are stored with the user's account and compared with hashes for new users to provide contact and referral features; hashing does not make this data anonymous.
- User content and communications. Cashout processes uploaded photos and videos, captions, comments, profile content, business descriptions, direct messages, and content submitted in reports or customer-support requests.
- Activity, advertising-attribution, and purchase history. Cashout processes product interactions, videos viewed and viewing duration, Dough transactions, coupons acquired, redemptions, order totals, and associations between business content and later redemptions.
- Merchant personnel data. Where a business invites staff to the Service, the invited individual provides a name and in-application photograph, as described in Section 7.
- Device, performance, and diagnostic data. Device and app identifiers, device model, operating-system and application version, performance measurements, crash logs, analytics events, and, where notifications are enabled, a push-notification token.
3. Purposes of Processing
Cashout processes personal information to: (a) operate the Service, including accounts, Dough rewards, coupon wallets, and redemptions; (b) measure content effectiveness by associating video views with subsequent redemptions; (c) provide business users with aggregate, group-level insights that do not identify any individual student; (d) deliver notifications the user has enabled, which the user may disable in the application or in operating-system settings; (e) detect, investigate, and prevent fraud and abuse; and (f) comply with legal obligations.
4. Pseudonymization; Aggregation Threshold
Student users appear within the Service under a chosen nickname. Business users receive only aggregated, de-identified metrics; no interface within the merchant product discloses an individual student. Attribution and redemption records identify students by one-way hash. Demographic trends are disclosed to a business only after the number of consenting students exceeds a threshold designed to prevent the singling out of any individual; below that threshold, no demographic information is disclosed.
5. Disclosures
Cashout discloses personal information only: (a) to service providers processing on Cashout's behalf and under contractual restrictions, including Google Firebase (authentication, analytics, hosting, database, storage, performance, crash reporting, and push delivery), Resend (transactional and lifecycle email), and Stripe, Inc. (merchant billing and tax processing, including merchant contact and business-address information; Cashout does not receive or store full payment-card numbers); (b) to merchants, solely in the form of aggregate metrics and anonymous group trends as described in Section 4; and (c) where required by law or reasonably necessary to protect the rights, property, or safety of Cashout, its users, or the public. Merchant insight text in this release is generated deterministically from allowlisted Cashout metrics; it is not sent to a generative-AI provider. Cashout does not sell, rent, or trade personal information and does not permit service providers to use this information for cross-context behavioral advertising.
6. Rights and Choices
- Demographics. Users may edit or withdraw shared demographic details at any time within the application; withdrawal deletes the stored record.
- Notifications. Users may opt in or out within the application or in operating-system settings.
- Deletion. Users may delete their account within the application or by written request to support@cashoutmobile.com. Cashout deletes personal information within thirty (30) days of a verified request; aggregate statistics that cannot reasonably identify the user may be retained.
- Access and correction. Users may request access to or correction of their personal information at the address above. Cashout will honor rights afforded by applicable law.
7. Merchant Personnel Data
Where a business invites staff to its scanning role, the invited individual provides a name and photograph within the application. Such information is visible only to that business's owner and managers, and is not disclosed to students or to other businesses. As between Cashout and the business, the business is the controller of such data and is responsible for providing notice to, and where required obtaining consent from, its personnel. Upon removal of a personnel account by the business, the associated photograph is deleted from active storage.
8. Security
Personal information is encrypted in transit (HTTPS/TLS) and stored on infrastructure maintained by Google Firebase. Reward balances, redemptions, and billing meters are computed server-side and are not modifiable from client devices. No method of transmission or storage is guaranteed to be secure, and Cashout does not warrant absolute security.
9. Age Restriction
The Service is intended for university students who are at least sixteen (16) years of age. Cashout does not knowingly collect personal information from any individual under sixteen. A parent or legal guardian may contact Cashout at the address in Section 11 regarding an eligible user's privacy request; Cashout will verify the requester's authority before acting. If you believe an individual under sixteen has provided personal information, contact Cashout immediately.
10. Changes to this Policy
Cashout may amend this Policy from time to time. Material changes will be announced within the application or by email at least fourteen (14) days before their effective date. Continued use of the Service after the effective date constitutes acceptance of the amended Policy.
11. Contact
Cashout Mobile LLC, Columbus, Ohio, USA · support@cashoutmobile.com