Privacy Policy
App: Code Cards: Loyalty Wallet
Developer: Funkrom
Effective date: 17 July 2026
Last updated: 17 July 2026
1. Introduction
This Privacy Policy explains how Funkrom (“Developer”, “we”, “us” or “our”) handles information in connection with the "Code Cards: Loyalty Wallet" mobile application (“App”).
The App is an offline-first utility that allows users to create, organise, display, back up, and restore barcode and QR-code cards, such as loyalty or membership cards.
The current version of the App does not require an account and does not send card information to a server operated by the Developer.
2. Important security and encryption warning
The App does not apply application-level encryption to card information stored in the App’s local database.
Backup files created by the App are not encrypted. They contain card names, barcode or QR-code values, and associated information in readable plaintext JSON format.
Your device operating system or a cloud-storage provider may independently apply device, storage, transport, or account security. Those protections are supplied and controlled by the device manufacturer or cloud provider—not by the Developer—and we do not guarantee their availability or effectiveness.
The App is not designed or suitable for storing confidential, secret, security-critical, or highly sensitive information.
You must not use the App to store information such as:
- passwords or passphrases;
- authentication credentials;
- private cryptographic keys;
- recovery phrases or seed phrases;
- one-time authentication codes;
- financial-account or payment-card details;
- government identification numbers or documents;
- medical or health information;
- workplace or commercial secrets;
- security-access credentials;
- private tickets, passes, or codes where unauthorised use could cause significant harm; or
- any information that requires encrypted or regulated storage.
Anyone who gains access to your unlocked device, its application data, or an exported backup file may be able to read or use the information stored in the App.
You are responsible for deciding whether particular information is appropriate to store in the App and for securing your device, cloud accounts, and backup files.
3. Information processed by the App
The App may process information that you choose to enter, scan, import, organise, or back up, including:
- card names;
- barcode and QR-code values;
- barcode or QR-code formats;
- folder names;
- card colours and display preferences;
- favourite status and sorting information;
- creation and modification timestamps;
- deletion records used to support backup and restoration;
- the App version and export timestamp included in backup files; and
- limited diagnostic information described below.
A barcode or QR-code value may identify or be associated with a particular person, membership, account, entitlement, ticket, or retailer relationship. You should treat such values as potentially sensitive even when they do not display your name.
4. Where information is stored
4.1 Local storage
Card and folder information is stored locally on your device in the App’s database.
The Developer does not operate a backend service that receives or synchronises this information.
Local information ordinarily remains on your device until you:
- delete the relevant card or folder;
- clear the App’s storage;
- uninstall the App; or
- erase or reset the device.
Your device operating system may retain temporary files, system backups, or recoverable data according to its own behaviour and settings.
Because the App does not maintain a user account or server-side copy, the Developer generally cannot:
- view your locally stored information;
- recover lost cards;
- reset or restore your information;
- remotely delete your information; or
- transfer your information to another device.
4.2 Backup files
The App may allow you to create a backup file containing your folders, card names, card values, formats, colours, and related metadata.
Backup files are not encrypted and are readable plaintext files.
Depending on your device and selections, you may save or send a backup using:
- iCloud Drive;
- Google Drive;
- Dropbox;
- a device file-storage location;
- email;
- AirDrop;
- another application;
- another cloud-storage provider; or
- another destination available through your device’s share sheet or document picker.
When you select one of these destinations, the relevant operating-system provider or third-party service may receive and process the backup. Its privacy policy, security practices, account settings, and terms apply independently.
The Developer does not control how a selected third-party provider stores, processes, retains, synchronises, or discloses a backup.
You are responsible for:
- selecting an appropriate backup destination;
- protecting the destination account;
- checking who can access shared files or folders;
- retaining backups only for as long as necessary;
- deleting obsolete backups; and
- ensuring that a backup is not accidentally emailed, shared, or made publicly accessible.
Deleting information from the App does not delete backup copies that you previously exported. You must separately delete those copies from every destination where they were saved.
5. Camera access
The App may request access to your device’s camera so that you can scan a barcode or QR code.
Camera access is used only when you initiate the scanning function. Camera frames are processed on the device to identify a code.
The App does not intentionally transmit camera images or live camera footage to the Developer.
The App stores the decoded value and selected card details—not the continuous camera recording.
You can deny or withdraw camera permission through your device settings. Manual entry may remain available when camera access is unavailable.
6. Photo-library and file access
The App may allow you to select an image, screenshot, or file containing a barcode or QR code.
The selected item is processed on the device to attempt to identify the code. The App ordinarily stores the decoded value and card details rather than retaining an additional copy of the selected image.
Your operating system or selected file provider may separately record or process your interaction according to its own privacy practices.
7. Diagnostic information
The App may generate limited diagnostic records to assist with troubleshooting.
In the current version:
- diagnostic records are maintained locally in memory;
- remote analytics and remote crash-reporting services are not enabled;
- diagnostic records are not intentionally uploaded to the Developer;
- raw barcode and QR-code values are intended to be redacted from diagnostic messages; and
- diagnostic records may include general events, error categories, App routes, App components, and technical failure information.
You may choose to manually share diagnostic information with the Developer when requesting support. Before doing so, review the information and remove anything you do not wish to disclose.
Diagnostic redaction reduces risk but cannot be guaranteed to detect every possible sensitive value.
If analytics, remote crash reporting, account functionality, server synchronisation, advertising, or other network services are introduced, this Privacy Policy will be updated before those services are enabled where required.
8. Information we do not intentionally collect
In the current version, the Developer does not intentionally collect through the App:
- your name, email address, or contact list;
- precise or approximate location;
- advertising identifiers;
- device identifiers for tracking;
- browsing history;
- payment-card information;
- health information;
- card or barcode values through a Developer-operated server;
- behavioural analytics;
- advertising profiles; or
- information used for cross-app or cross-site tracking.
The App does not sell personal information and does not use card information for advertising.
9. App stores and operating-system providers
Apple, Google, your device manufacturer, payment provider, telecommunications provider, or app-store operator may independently process information concerning:
- App downloads and installations;
- purchases and refunds;
- subscriptions or licences, where applicable;
- device and operating-system information;
- App performance;
- crash information;
- store-account information; and
- interactions with the relevant store.
That processing is performed under the provider’s own privacy policy and is not controlled by the Developer.
We do not receive your full payment-card details from an app-store operator.
10. Third-party storage and services
The App may interact with operating-system features or services supplied by third parties, including camera services, photo pickers, document pickers, sharing interfaces, cloud-storage providers, and app stores.
The inclusion of or compatibility with a third-party service does not mean that the Developer controls or endorses that service’s privacy or security practices.
You should review the privacy policy and security settings of each service you choose to use.
11. Disclosure of information
Because the current version does not send your card information to a Developer-operated service, we do not ordinarily possess that information and cannot ordinarily disclose it.
We may receive information when you voluntarily contact us, such as:
- your email address;
- the content of your support request;
- screenshots or diagnostic information you choose to send; and
- any other information you voluntarily provide.
We may use information received through a support request to:
- respond to you;
- investigate a reported problem;
- improve the App;
- maintain records relating to the request; or
- comply with applicable law.
We may disclose information we actually hold where reasonably necessary to:
- comply with a lawful court order, warrant, or legal requirement;
- obtain professional legal, accounting, or technical advice;
- investigate fraud, misuse, or threats to safety;
- protect our legal rights; or
- complete a business restructuring or transfer, subject to applicable law.
12. International processing
The App does not intentionally transfer card information to the Developer.
A cloud-storage, email, sharing, or app-store provider selected by you may process information in Australia or another country. The location and safeguards depend on the provider and your account configuration.
You should not export a backup to a service or jurisdiction that does not provide a level of protection appropriate for the information contained in the backup.
13. Data security
We take reasonable steps within the design of the App to reduce unnecessary disclosure, including local-first processing and redaction of barcode values from diagnostic messages.
However:
- local card information is not encrypted by the App;
- backup files are not encrypted;
- no storage system is completely secure;
- mobile devices can be lost, stolen, compromised, or accessed by other people;
- cloud accounts can be compromised;
- shared files can be sent to the wrong recipient; and
- operating-system backups may create additional copies.
You should use available device-security controls, including:
- a strong device passcode;
- biometric access where appropriate;
- current operating-system security updates;
- secure cloud-account credentials;
- multi-factor authentication for cloud accounts;
- restricted file-sharing permissions; and
- deletion of backup files that are no longer required.
These measures do not change the fact that the App itself does not provide application-level encryption.
14. Data loss and recovery
You are responsible for maintaining any backup you consider necessary.
Backups may fail, become corrupted, be incomplete, become incompatible, be overwritten, or be unavailable because of a provider or device problem.
The Developer does not guarantee that any card, backup, or deleted information can be recovered.
Before deleting the App, replacing a device, resetting a device, or relying on a restore, you should verify that an appropriate backup exists and can be accessed.
15. Children
The App is not specifically directed to children.
A person who has not reached the age at which they can independently consent to these practices should use the App only with the permission and supervision of a parent or legal guardian.
Parents and guardians should consider whether an unencrypted card-storage application is appropriate for the child.
16. Your choices and rights
Depending on applicable law, you may have rights concerning personal information that the Developer actually holds about you.
Because card information is ordinarily stored only on your device or in destinations selected by you, requests concerning that information may need to be exercised directly through:
- the App;
- your device settings;
- your cloud-storage account;
- the recipient of a shared file; or
- the applicable service provider.
For information submitted directly to the Developer through a support request, you may contact us to request access, correction, or deletion, subject to applicable legal exceptions.
17. Changes to this Privacy Policy
We may update this Privacy Policy when the App’s functionality, data practices, legal requirements, or third-party integrations change.
The updated policy will display a revised “Last updated” date. Where required, we will provide additional notice or request consent.
You should review the policy after installing an update, particularly if the App introduces accounts, remote synchronisation, analytics, crash reporting, advertising, or new backup methods.
18. Contact and complaints
Questions, access requests, correction requests, deletion requests, and privacy complaints may be sent to:
Developer: Funkrom
Email: [email protected]
Please include enough information to identify and investigate your request, but do not email us a full barcode value, backup file, password, private key, or other confidential information.
We will assess privacy complaints and respond within a reasonable period.
If you remain dissatisfied, you may have the right to contact the privacy or consumer-protection authority applicable in your jurisdiction.