Privacy Policy

Last updated June 2026

Your trust is the product. This policy explains what data GoJas Enterprises LLC, which operates Point Wizard (“Point Wizard,” “we,” “us”), collects, why we collect it, how we share it, and the control you have over it. It applies to our website, apps, and services (the “Service”).

1. Information we collect

Account information you provide: your name, email, password (stored only as a secure hash by our authentication provider), home airport, and travel preferences.

Loyalty and points data: the programs you add, balances, tiers, and expiration dates — entered by you or, where you connect an account, retrieved on a read-only basis through our connectivity provider (Plaid).

Financial connection data: when you link an account, we receive read-only information such as balances and transactions. We never receive or store your bank or loyalty-program passwords, and we cannot move money or make transactions.

Payment information: handled by our payment processor, Stripe. We do not see or store your full card number — we keep only limited billing details and identifiers needed to manage your subscription.

Usage and device data: basic, privacy-respecting analytics and technical logs (such as device, browser, and pages used) that help us run and improve the Service.

Communications: messages you send us, such as support requests.

2. How we use your information

To provide the Service: calculate the value of your points, find award redemptions matched to your balances, alert you before points expire, and — when you approve a booking — prepare the transfer and award details so you can complete the reservation yourself.

To operate our business: process subscriptions, provide support, secure the Service, prevent fraud and abuse, comply with legal obligations, and improve our features.

We do not sell your personal information.

3. AI-assisted features

Some features use third-party AI providers to generate recommendations and summaries. When you use them, we send the limited information needed for that task (such as relevant balances or a trip request). We do not include more personal data than necessary to produce the result you asked for.

4. How we share information

Service providers: we share data only with the providers needed to run the Service — for example payment processing (Stripe), account connectivity (Plaid), AI processing, hosting, and email delivery — and only to the extent required to deliver the Service.

Partner agencies: if you join through a partner agency, that agency can see that you are a referred client and high-level account status — not your credentials, linked-account logins, or full financial detail.

Legal and safety: we may disclose information if required by law or to protect the rights, safety, or property of our users or Point Wizard.

Business transfers: if we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.

5. Plaid

When you connect a financial account, you do so through Plaid Inc. Plaid processes your connection on a read-only basis and handles your data in accordance with Plaid’s own end-user privacy policy. We encourage you to review it before connecting an account.

6. Data retention

We keep your data while your account is active and as needed to provide the Service and meet legal, accounting, or reporting obligations. You can disconnect any linked account at any time, and you can request deletion of your account and associated data.

7. Security

We protect your data with industry-standard measures, including encryption in transit (TLS) and at rest, access controls, and read-only financial connections. No method of transmission or storage is 100% secure, but we work to protect your information and to limit who can access it.

8. Your rights & choices

You can access, correct, export, or delete your personal data, and you can object to or restrict certain processing. To exercise any of these, contact us and we will respond as required by law.

California residents (CCPA/CPRA): you have the right to know what personal information we collect, to request deletion or correction, and to opt out of “sales” or “sharing” of personal information. We do not sell your personal information. You will not be discriminated against for exercising these rights.

EU/UK residents: where applicable, we process personal data to perform our contract with you, for our legitimate interests in operating and improving the Service, to comply with legal obligations, or with your consent, and you have corresponding rights under the GDPR/UK GDPR.

9. Cookies

We use cookies and similar technologies to keep you signed in and to understand usage. You can control non-essential cookies — see our Cookie Policy for details.

10. Children’s privacy

The Service is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

11. International users

We are based in the United States, and your information is processed and stored in the U.S. If you access the Service from elsewhere, you understand your data will be transferred to and handled in the U.S.

12. Changes to this policy

We may update this policy as the product and the law evolve. We will post the new effective date at the top, and for material changes we will provide reasonable notice.

13. Contact

Questions about privacy, or want to exercise a data right? Email contact@thepointwizard.com.

GoJas Enterprises LLC, 8256 Limetree Ct, Orlando, FL 32836, USA.

This page is a plain-language template for an early-stage product and is provided for transparency, not as legal advice. Questions? Email contact@thepointwizard.com.