Privacy Policy
Last updated 20 September 2026
In short: we collect your email and name, your country, your points and survey history, security data such as your IP address, and the payout destination you enter. Research partners receive a pseudonymous member ID, never your email or payout details. We do not sell your data, and you can request access or deletion at any time.
1. Introduction and scope
Rewario Surveys ("Rewario Surveys", "we", "us", "our") operates the paid survey rewards website at rewariosurveys.com. This Privacy Policy explains what personal data we collect, why we collect it, the legal bases we rely on, who we share it with, how long we keep it, how we protect it, and the rights you have.
This policy applies to the website, to member accounts, and to our emails. It does not apply to what happens inside a research partner's survey, which that partner controls under its own policy (see section 5). It forms part of our Terms of Service.
For the purposes of the EU and UK GDPR, Rewario Surveys is the controller of the personal data described here. Contact details are in section 13.
2. Personal data we collect
We collect only what the Service needs in order to run:
- Registration and identity data: your email address, and where you use Google Sign-In, the name and profile picture your Google account exposes. We never receive your Google password. Where you register with an email address, your password is stored only as a salted hash by our authentication provider.
- Profile data: the country you select and any optional details you add to your account.
- Earning and balance data: your points ledger, survey completion, screen-out and reversal records, streaks, levels and redeemed bonus codes.
- Referral data: your referral code, who referred you, the members you referred, and commission entries.
- Redemption data: the reward claimed, the amount, the claim status, and the payout destination you supply (for example a PayPal or gift-card email address).
- Support data: the messages, attachments and contact details you send us through Help & Support.
- Technical and security data: IP address and derived approximate location and network type (used to detect VPN, proxy and hosting traffic), device and browser information, session records, and the metadata contained in research-partner callbacks used for auditing and fraud prevention.
- Consent data: your cookie choices and the time they were recorded.
3. Where the data comes from
Most data comes from you directly, when you register, complete your profile, claim a reward or contact support. Some is generated automatically by using the Service, such as ledger entries and session records. Some comes from third parties: your sign-in provider confirms your identity, research partners send completion and reversal notifications, and an IP-intelligence service tells us whether a connection appears to use a VPN, proxy or data centre.
4. How and why we use your data
We use your personal data to create and operate your account, authenticate you, credit and audit points, apply partner reversals, run streaks, levels, bonus codes and the referral programme, review and fulfil reward claims, respond to support requests, detect and prevent duplicate accounts and fraudulent activity, secure the Service, comply with legal and accounting obligations, and send you service and, where you have agreed, promotional emails.
Where the EU or UK GDPR applies, our legal bases are:
- Performance of a contract: operating your account, crediting points, reviewing and fulfilling reward claims, and providing support.
- Legitimate interests: fraud and abuse prevention, VPN and duplicate-account detection, securing and improving the Service, and defending legal claims. We balance these interests against your rights and keep the processing to what is necessary.
- Consent: optional cookies, marketing emails and any optional feature we ask you to opt into. You may withdraw consent at any time.
- Legal obligation: financial record-keeping, responding to lawful requests, and honouring your data rights.
5. Survey research partners
To match you with studies we pass a pseudonymous member identifier and, where required for targeting, coarse attributes such as your country, to our research partners (currently CPX Research and TheoremReach). We do not send your name, email address, password or payout details to a survey partner.
Inside a partner's survey wall, that partner and its research clients collect the profiling and survey answers you choose to give, together with technical data such as IP address and device details for quality and fraud checks. For that processing they act as independent controllers under their own privacy policies, and any request about survey answers should be addressed to them.
Partners return completion, reward, screen-out and reversal information to us over signed server-to-server callbacks so that we can credit or adjust your balance.
6. Other recipients and processors
We share personal data with a limited set of service providers who act as processors on our behalf, under contract and only on our instructions: authentication, database and file hosting; application hosting and content delivery; transactional email delivery; IP-intelligence for fraud screening; and the payout and gift-card providers used to deliver a reward you claim, which receive only what is needed to send that reward.
We may also disclose data where the law requires it, in response to a valid legal request, to protect our rights or the safety of others, to investigate fraud, or in connection with a merger, acquisition or transfer of the business, in which case we will notify you.
We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it for advertising profiling.
7. International transfers
Our providers and research partners may process data outside your country, including in the United States. Where personal data leaves the EEA or the UK we rely on an appropriate safeguard, normally the European Commission's Standard Contractual Clauses together with the UK Addendum, or the provider's certification under an approved transfer framework, along with additional technical measures such as encryption in transit. You may request more information about the safeguards used for a specific transfer.
8. Cookies and similar technologies
We use strictly necessary cookies and browser storage to keep you signed in, protect the session against abuse, remember your interface preferences and record your consent choices. Optional analytics or functional storage is only set after you agree in the cookie banner, and you can change or withdraw your choice at any time on our Cookie Policy page. We do not use advertising or cross-site tracking cookies. Blocking strictly necessary storage will prevent sign-in from working.
9. How long we keep data
We keep account, profile, points-ledger, completion and referral records for as long as your account is open, because they are needed to run and audit your balance.
After you close your account we delete or anonymise your profile and keep only what remains necessary: redemption and ledger entries for accounting and tax purposes, normally up to 7 years where local law requires it, and a hashed identifier retained to prevent duplicate re-registration and repeat fraud.
Support correspondence is kept while your request is open and for a reasonable period afterwards for reference. Security and fraud logs are kept for up to 24 months. Consent records are kept for as long as needed to demonstrate compliance.
10. Your rights
Depending on where you live, you may have the right to access a copy of your personal data, correct inaccurate data, delete it, restrict or object to certain processing (including profiling used for fraud screening), withdraw consent, receive your data in a portable format, and not be discriminated against for exercising these rights. In the EEA and the UK you may also lodge a complaint with your local supervisory authority.
If you are a California resident, you have the right to know, delete and correct your personal information and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use sensitive personal information for inferring characteristics.
To exercise a right, contact us through the Help & Support page in your account or at support@rewariosurveys.com. We verify requests against the email address on the account and respond within 30 days, extendable where the law allows. Deleting your account forfeits any unredeemed points, and some records must be retained for the reasons in section 9. You may use an authorised agent where local law allows it.
11. Security
Data is held in a managed, access-controlled database with row-level security so that members can read only their own records, and administrative access is restricted to authorised accounts with multi-factor sign-in. Passwords are stored only as salted hashes. Balance-changing partner callbacks are cryptographically signed, verified, and de-duplicated by transaction identifier. All traffic to the site is encrypted in transit with TLS.
No online service can guarantee absolute security. If a breach affects your personal data and is likely to pose a risk to you, we will notify you and the competent authority as required by law, normally within 72 hours of becoming aware of it.
12. Children's privacy
The Service has a minimum age of 16 and is not directed at anyone under 16. We do not knowingly collect personal data from children. If we learn that a minor has registered, we close the account and delete the associated data. If you believe a child has provided us with data, contact us and we will act promptly.
13. Changes and contact
We may update this policy as the Service changes. The date at the top of this page identifies the current version, and material changes will be announced in the app or by email before they take effect.
Privacy questions, data-subject requests and complaints: Help & Support inside your account, or support@rewariosurveys.com. We reply by email.
