PerkTrack
PerkTrack Privacy Policy
How Summer Jib LLC handles information for PerkTrack, the credit-card benefit and wallet value tracking app.
- Effective date
- April 26, 2026
- Last updated
- July 26, 2026
- Contact
- admin@summerjib.com
Who we are
Summer Jib LLC, a Wyoming limited liability company, operates PerkTrack. This policy explains how we collect, use, share, and protect information when you use PerkTrack, related website pages, support channels, and app services.
Information PerkTrack collects
- Account information, such as Apple Sign In subject identifier, email address if Apple provides it, display name, internal user ID, session tokens, encrypted Apple refresh token when needed for Sign in with Apple revocation during account deletion, account status, support requests, and feedback submissions you choose to send.
- Legal and eligibility information, such as 18+ confirmation, accepted policy version, accepted terms version, acceptance timestamp, app version, platform, and the policy and terms URLs shown at acceptance.
- Plaid-linked financial information, such as linked institution metadata, credit account names, official names, account masks, account type and subtype, balances, credit limits, transaction history, merchant names, statement descriptions, dates, amounts, categories, pending status, payment channel, transaction-location metadata when Plaid provides it, merchant website/logo metadata, sync status, relink status, and account health signals.
- Debt-payoff information you choose to enter, such as a debt name and type, current balance, annual percentage rate, monthly minimum payment, and optional next due date. User-entered debt is kept separate from Plaid records and is deleted when you remove it or delete your account.
- Plaid connection information, such as item identifiers, encrypted access tokens, link token status, webhook events, institution identifiers, sync cursors, retry state, duplicate-account checks, and audit events. PerkTrack does not receive or store your bank login credentials.
- Manual and preserved card information, such as selected card, card nickname if entered, ownership type, optional last four digits, year opened, permanent card identity, matching or validation status, and last-known card or benefit records retained for manual tracking after a Plaid connection is removed.
- Benefit, catalog, and recommendation information, such as backend-delivered card artwork, issuer and merchant logos, card catalog matches, benefit rules and eligibility dates, statement-credit usage estimates, cycle windows, remaining value, best-card recommendations, merchant interaction events, and reminder state.
- Paywall and value-estimate information, such as selected or connected cards, estimated annual benefit value, wallet-coverage selection, billing-period selection, suggested or custom amount selection, promotional-code events, and the subscription product presented for purchase.
- Local app-cache information, such as the last-known dashboard, card, profile, perk, activity, sync-health, and recommendation payloads stored on your device so PerkTrack can show recent state while refreshing. This local cache is cleared by sign-out, account deletion, app data removal, or uninstall, and may also be removed by iOS.
- Purchase, plan, entitlement, and limit-enforcement information, such as App Store product identifiers, RevenueCat entitlement status, membership tier, trial or subscription state, Plaid link attempts, sync frequency, request counts, rate-limit events, cooldown state, duplicate-link checks, and fraud or abuse review signals. Apple processes App Store payments, and we do not receive your full payment card number.
- Ask Perk assistant information, when you use that feature, such as your current question, up to eight prior messages from the open chat sheet, locale, timezone, an optional active-benefit identifier, server-reconstructed benefit or financial facts needed to answer the question, the response origin, approved in-app action, and source metadata when external grounding is used. Raw Ask Perk chats and model-provider request or response bodies are not stored in PerkTrack's database, analytics, discrepancy records, or email digests. PerkTrack separately stores limited account-linked usage metadata—an assistant session identifier, timestamp, plan tier, question character count, prior-turn count, response origin, provider/model or fallback route, high-level approved action type, latency, token/search/citation counts, verifier result, circuit state, and estimated cost—to measure reliability, feature use, and provider cost. This metadata does not contain the question, answer, benefit or merchant name, balance, transaction, or other financial value.
- Device and notification information, such as APNs device token when you allow push notifications, notification preferences, delivery/read/open events, platform, environment, app version, and account-linked security audit events.
- Anonymous product interaction and diagnostic summaries, such as onboarding or paywall step events, random session IDs that are not tied to your account, sync-refresh phase, error category, timing, network status, item-status counts, app version, and app build. These anonymous reports do not include your account ID, Plaid access token, bank credentials, transaction details, or raw backend responses.
How PerkTrack uses information
- Create and secure your account, authenticate sessions, revoke Sign in with Apple authorization when available during account deletion, and support account deletion.
- Connect supported institutions through Plaid, sync credit account and transaction data, map cards, monitor benefit usage, estimate remaining statement-credit value, surface deadlines, and identify missed value.
- Support manual card setup, conversion of last-known connected data to manual tracking after disconnection, wallet organization, dashboards, claimed-value calculations, best-card recommendations, reminders, and account-link health checks.
- Deliver and update card artwork, merchant logos, benefit descriptions, eligibility dates, issuer terms, catalog corrections, and similar content from our backend without requiring a new app version where the installed app supports that content format.
- Enforce membership limits, Plaid sync controls, card limits, rate limits, service-protection controls, and abuse-prevention rules.
- Provide Ask Perk to eligible members by interpreting questions, selecting read-only PerkTrack information, explaining backend-calculated facts, answering contextual follow-ups while the chat sheet remains open, and returning approved in-app navigation actions.
- Troubleshoot sync issues, detect stale or duplicate links, respond to feedback, enforce security controls, maintain audit logs, measure Ask Perk sessions and daily, weekly, or monthly usage, monitor AI reliability and provider cost, improve product quality with minimized interaction and diagnostic summaries, and comply with law.
Ask Perk and AI-provider processing
Ask Perk uses OpenAI as its primary model provider and Google Gemini as an independent fallback through PerkTrack's server to interpret eligible members' questions and explain relevant PerkTrack information. PerkTrack's backend independently authenticates the account, checks the subscription entitlement, reconstructs relevant read-only information, and calculates balances, dates, totals, recurring normalization, budgets, and subscription access. The models cannot change your PerkTrack data.
A normal Ask Perk request may include your current question, up to eight prior turns from the open chat sheet, locale, timezone, an optional active-benefit identifier, and the limited server-reconstructed PerkTrack facts needed to answer. PerkTrack does not persist raw chats or provider request and response bodies, and the current conversation ends when the Ask Perk sheet closes.
PerkTrack retains the limited Ask Perk usage metadata described above for up to 400 days so it can compare daily, weekly, monthly, and year-over-year feature operation. It is deleted sooner when the associated account is deleted. Protected operator reports use a stable pseudonym instead of displaying an email, Apple identity, or raw internal user ID.
PerkTrack uses provider web-search grounding only when internal information cannot establish a current public benefit term or merchant-eligibility fact. That separate request is minimized to the public card or benefit name and the external question. It does not include your identity, balances, transactions, linked institutions, or raw financial history. PerkTrack sends OpenAI Responses requests with application-state storage disabled; OpenAI states that API data is not used to train its models unless an organization opts in, while default abuse-monitoring records may be retained for up to 30 days. A Gemini fallback request is subject to Google's applicable processing and grounding terms. Grounded responses may display source links and, when Gemini is used, Google Search Suggestions.
If a supported public source conflicts with PerkTrack's catalog, PerkTrack may keep a de-identified review record containing catalog identifiers, compared claims, source links, model route, timestamps, and occurrence count. This record does not include your identity, raw prompt, chat history, or personal financial values, does not automatically change the catalog, and expires after 30 days unless reviewed sooner.
Ask Perk choices and limitations
Ask Perk is limited to questions about PerkTrack, connected financial activity, card benefits, recurring charges, budgets, and card-use comparisons. It may decline unrelated or high-risk requests and may use Google Gemini or PerkTrack's deterministic local responder if OpenAI is unavailable.
AI and externally grounded answers can be incomplete, outdated, or wrong. Your issuer's current terms, merchant eligibility, transaction records, and PerkTrack's backend-calculated account facts should be reviewed before relying on a benefit or purchase decision. Ask Perk is not tax, legal, lending, credit, investment, or personalized financial advice.
PerkTrack eligibility and children
PerkTrack is intended only for users who are at least 18 years old and legally able to connect the financial accounts and cards they choose to use with PerkTrack.
We do not knowingly collect personal information from anyone under 18 through PerkTrack. If you believe someone under 18 used PerkTrack, contact us and we will take appropriate steps, subject to legal, security, fraud-prevention, backup, billing, and dispute obligations.
Plaid and bank credentials
PerkTrack uses Plaid to let you connect supported financial institutions. Plaid handles the connection flow and user consent with your institution. PerkTrack receives data authorized through Plaid, but PerkTrack does not receive or store your bank username or password.
If you disconnect an institution, PerkTrack requests removal of the applicable Plaid connection and stops future automatic syncing for that connection. PerkTrack may preserve the last information already received, including card identity, benefit records, and claimed-value history, as manual-tracking data so you can continue tracking it. Preserved data does not continue updating from Plaid and remains subject to account deletion, retention, and legal exceptions described in this policy.
Plaid, provider, and security incident risk
Plaid, financial institutions, Apple, RevenueCat, cloud hosts, and other providers operate systems that PerkTrack does not control. A compromise, outage, configuration error, or unauthorized access involving one of those providers could affect PerkTrack data, connections, availability, or functionality even if Summer Jib LLC follows reasonable safeguards.
We do not represent or warrant that Plaid or any other provider is immune from a breach, and we do not promise 100% security. We will use reasonable efforts to protect information under our control and to respond to known incidents, but we cannot prevent or control every act or omission of an independent provider. This disclosure does not reduce any privacy, security, breach-notification, or consumer rights that cannot be waived under applicable law.
You may disconnect an institution in PerkTrack, revoke a connection through your financial institution or Plaid's available consumer controls, secure your financial accounts, and contact us if you suspect unauthorized activity. Disconnecting stops future PerkTrack sync for that connection but does not necessarily erase information already received; account deletion is described separately below.
Device authentication and local cache
PerkTrack can require Face ID, Touch ID, or device passcode before showing the app dashboard after setup. This app-open authentication uses Apple's local device authentication and does not send biometric data to Summer Jib LLC.
To avoid a blank dashboard while fresh sync runs, PerkTrack may keep a protected last-known dashboard cache on your device. The cache is used to display recent state while the app refreshes from the backend, and it may be cleared when you sign out, delete your account, remove app data, uninstall the app, or when iOS purges local cache storage.
Financial data sensitivity
PerkTrack is designed around sensitive financial information. We use financial data only to provide and improve PerkTrack, maintain security, troubleshoot account-linking, enforce limits, prevent fraud, and comply with legal obligations.
PerkTrack is not a bank, card issuer, creditor, lender, credit repair organization, credit reporting agency, investment adviser, tax adviser, financial adviser, money transmitter, payment processor, or legal adviser.
Notice at collection and sources of information
We collect the categories of information described in this policy directly from you, from your device and app activity, from your account and subscription status, from support communications, and from service providers that you authorize or that help us operate the services.
We collect and use information for the purposes described in this policy, including app functionality, personalization, security, fraud prevention, troubleshooting, analytics, customer support, legal compliance, and enforcing our terms and membership limits.
Categories, purposes, recipients, and retention
The app-specific sections below identify the main categories of personal information we collect. We use those categories for the purposes listed in this policy and may disclose them to service providers, processors, contractors, platform providers, professional advisers, regulators, or transaction counterparties only as described here or as otherwise permitted by law.
We retain each category only as long as reasonably necessary for the purpose collected, including active account use, feature delivery, support, legal compliance, security, fraud prevention, billing, dispute handling, backups, and legitimate internal records. Specific retention periods may vary by category, legal requirement, provider configuration, and whether you delete your account or request deletion.
How we share information
No sale or targeted-advertising sharing: we do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We may share information with service providers that help us operate the apps and website, including cloud hosting, authentication, analytics, crash reporting where configured, payments, app security, email delivery, and customer support.
We may disclose information if required by law, to protect users or the services, to investigate abuse or security issues, or as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections.
Security and retention
We use reasonable technical and organizational safeguards designed to protect personal information, including encryption in transit and access controls. Some sensitive credentials, such as Plaid access tokens used by PerkTrack, are encrypted before storage. These safeguards reduce risk but cannot eliminate every risk, and we do not guarantee absolute security.
We keep information for as long as reasonably needed to provide the services, comply with law, resolve disputes, maintain security, and support legitimate business records. When you delete an account, we delete or de-identify account data unless retention is required or permitted by law, security, fraud prevention, backup integrity, billing records, or dispute handling.
Service protection, fraud prevention, and limit enforcement
We may process account, device, request, entitlement, usage, diagnostic, security, and support information to enforce membership limits, apply fair-use controls, rate limit requests, prevent automated or abusive activity, protect service reliability, troubleshoot issues, and investigate suspected fraud or security incidents.
When needed to protect users or the services, we may retain limited records related to security, fraud prevention, abuse investigations, chargebacks, billing, disputes, legal compliance, or enforcement even after an account deletion request, where permitted or required by law.
Automated processing and high-impact decisions
The services may use automated systems to parse labels, match products, score compatibility, organize transactions, estimate benefit usage, detect abuse, or personalize app experiences. These outputs are informational and may be reviewed, corrected, limited, or overridden by product logic, support review, provider data, or user choices.
We do not use Summer or PerkTrack outputs to make high-impact automated decisions about medical treatment, credit, lending, employment, housing, insurance, legal rights, government benefits, or similar eligibility decisions.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or additional information about how we process personal information. You may also have the right to complain to a privacy regulator.
California residents may request to know, access, delete, or correct personal information, opt out of sale or sharing, limit certain uses of sensitive personal information where applicable, and exercise privacy rights without discrimination. Because we do not sell personal information or share it for cross-context behavioral advertising, we do not provide a separate sale/share opt-out link.
Residents of other U.S. states may have similar privacy rights, including rights to access, delete, correct, obtain a portable copy of personal information, opt out of targeted advertising or sale where applicable, and appeal certain request decisions.
EEA and UK users may request access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent. Where we rely on legitimate interests, you may object to processing based on your particular situation.
To exercise privacy rights, contact admin@summerjib.com. We may need to verify your request before acting on it. Authorized agents may contact us using the same email address, and we may request proof of authorization and identity verification where permitted by law.
If we deny a privacy request and your law gives you an appeal right, reply to our decision email or contact admin@summerjib.com with "Privacy Appeal" in the subject line.
Security incidents and breach notices
We maintain safeguards designed for the type of information we process, but no app, network, cloud service, financial institution, or third-party platform is perfectly secure. Security incidents may occur despite reasonable safeguards, and we cannot promise that unauthorized access, disclosure, alteration, loss, or unavailability will never occur.
If we learn of a suspected incident, we may investigate, contain, remediate, preserve evidence, coordinate with affected providers, suspend connections or features, require reauthentication, rotate credentials, and take other steps we reasonably believe are appropriate. If applicable law requires notice, we will notify users, regulators, service providers, or other parties as legally required.
For Summer, some skin profile or scan-related information may be health-related consumer information. If a consumer health data incident triggers a specific notice law, including the FTC Health Breach Notification Rule where applicable, we will follow the applicable notice process without implying that Summer is covered by HIPAA unless that status is separately confirmed.
International processing
We operate from the United States and may process information in the United States and other countries where our service providers operate. Those countries may have different data protection laws than your place of residence.
Changes to this policy
We may update this policy as our apps, vendors, or legal requirements change. The updated version will be posted with a new last updated date. If changes are material, we will provide additional notice where required.