Privacy Policy — Steelmark Rewards
Effective date: 2026-04-26·Last updated: 2026-04-26
This Privacy Policy describes how Steelmark (“we”, “us”, “our”) collects, uses, and protects information when you use the Steelmark Rewards mobile application (“the app”) and the related backend services. Steelmark Rewards is a business-to-business application intended for authorised dealers, workshops, and executives within the Steelmark distribution network in Bangladesh.
If you have questions about this policy, contact us at admin@steelmark.com.bd.
1. Who we are
Steelmark Rewards is operated by Steelmark, headquartered at DK Tower (Level 5), 94 Bir Uttam CR Dutta Road, Banglamotor, Dhaka, Bangladesh. Phone: +88 02 9634417, 9634418, 58615557. Email: admin@steelmark.com.bd.
The app is published on Google Play by Rocks App on behalf of Steelmark, with rockssoft as the development and hosting partner. It is distributed exclusively through the Google Play Store under the package name bd.com.steelmark.reward.
The app is provided to identified business partners who have an existing commercial relationship with Steelmark. It is not a consumer product and is not marketed to the general public.
2. Information we collect
We collect only the information necessary to operate the rewards programme. We do not collect any data automatically from your device beyond what is listed below.
2.1 Information you provide directly
| Data type | Collected when | Why we need it |
|---|---|---|
| Full name | Registration, profile updates | Account identity, claim attribution |
| Email address | Registration, login | Account identity, authentication, claim notifications |
| Mobile phone number | Registration, profile updates | Account identity, alternate authentication, transactional SMS |
| Password | Registration, login (stored hashed) | Authentication |
| Workshop / dealer / executive affiliation | Registration, profile updates | Determining which rewards and claims you can access |
| Geographic location (manually entered) | Registration, location selection | Routing claims and rewards based on division / district / thana / union. We do not access your device's GPS or any location sensor. |
| Invoice files and supporting documents | When you submit a claim | Verifying claim authenticity for the rewards programme |
2.2 Information generated through your use of the app
| Data type | Source | Why we keep it |
|---|---|---|
| Account activity (logins, claim submissions, status changes) | Generated as you use the app | Audit trail, dispute resolution, programme integrity |
| Authentication tokens (JWT access and refresh tokens) | Issued by our backend at sign-in | Maintaining your authenticated session |
2.3 Diagnostic information
If the app crashes, we collect crash diagnostics through Google Firebase Crashlytics to help us identify and fix bugs. This typically includes:
- The Dart/Java stack trace at the moment of the crash.
- Device model, Android version, app version.
- A randomly generated installation identifier (not linked to your account).
Crashlytics does not capture the contents of forms, claim attachments, or any data you have entered. See Section 6 for more on third-party services.
2.4 What we do not collect
For clarity, the app does not collect any of the following:
- GPS or precise location.
- Contacts, calendar, or call logs.
- Photos or media beyond files you explicitly attach to a claim through the file picker.
- Microphone audio, camera images (other than files you explicitly upload), or sensor readings.
- Advertising identifiers (IDFA / GAID).
- Browser history or app usage outside Steelmark Rewards.
The app currently declares only the INTERNET permission in its Android manifest.
3. How we use your information
We use the information described in Section 2 for the following purposes:
- Account management — creating your account, authenticating you, and protecting your account from unauthorised access.
- Operating the rewards programme — recording claims, validating uploaded invoices, calculating rewards, processing fulfillment, and surfacing leaderboards and reports relevant to your role.
- Communication — sending transactional emails or SMS related to your account, claims, and rewards (e.g. claim approved, claim rejected, password reset). We do not use your contact details for marketing.
- Compliance and dispute resolution — maintaining audit logs of claim submissions, approvals, and status changes for the duration of the programme and for any subsequent dispute resolution.
- Quality and reliability — diagnosing and fixing bugs through crash reports as described in Section 2.3.
We do not use your information to build advertising profiles, sell data to third parties, or train machine-learning models.
4. Legal basis for processing
We process your information on the basis of the contractual relationship between Steelmark and your dealership, workshop, or executive organisation. Providing the data listed in Section 2.1 is necessary to participate in the rewards programme; without it, we cannot operate your account.
5. How long we keep your information
| Data type | Retention period |
|---|---|
| Active account information (Section 2.1) | For the lifetime of your account, plus up to 12 months after deactivation |
| Claim records and invoice attachments | For the duration of the rewards programme plus 7 years, to comply with Bangladesh tax and audit requirements |
| Authentication tokens (refresh tokens) | Up to 30 days, automatically rotated |
| Audit logs (account activity) | 7 years |
| Crashlytics diagnostic reports | 90 days, then automatically purged by Google |
If you ask us to delete your account (see Section 8), we will delete or irreversibly anonymise the active account data within 30 days, except where we are legally required to retain a record (in which case the data is moved to restricted storage and used only for the legal purpose).
7. Where your information is stored and how we protect it
- All data submitted by the app is sent over HTTPS only to backend servers operated for Steelmark by our hosting partner (see Section 6). The app rejects unencrypted
http://connections in production builds. - Relational data (accounts, claims, audit logs) is stored in a managed PostgreSQL database.
- Uploaded files (invoice images and PDFs) are stored in object storage (MinIO), accessed only through short-lived presigned URLs issued by our backend.
- Passwords are stored as one-way bcrypt hashes — Steelmark staff cannot read your password.
- Authentication uses signed JWT tokens with short-lived access tokens and rotating refresh tokens.
We follow industry-standard practices to protect your data, but no system is 100% secure. If we ever suffer a breach that affects your information, we will notify you in accordance with applicable Bangladeshi law.
8. Your rights and choices
You may at any time:
- Access or correct your information by editing your profile in the app, or by emailing admin@steelmark.com.bd.
- Request deletion of your account and the associated data by emailing admin@steelmark.com.bd from the email address on file. We will respond within 30 days. Records we are required to retain for legal or audit purposes will be moved to restricted storage and used only for the required purpose.
- Withdraw consent by deactivating your account. Note that deactivation will end your participation in the rewards programme.
- Lodge a complaint with the relevant Bangladeshi data protection authority if you believe we have mishandled your data.
To exercise any of these rights, email admin@steelmark.com.bd with a clear description of your request.
9. Children's privacy
The Steelmark Rewards app is intended for users aged 18 and over who have a business relationship with Steelmark. We do not knowingly collect information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us at admin@steelmark.com.bd and we will delete it.
10. International data transfers
Steelmark Rewards backend infrastructure is hosted on Google Cloud Platform in the Singapore (asia-southeast1) region. Crash diagnostics processed by Google Firebase Crashlytics may be processed in additional data centres operated by Google in other regions, including outside Asia.
By using the app, you acknowledge that your information is processed outside Bangladesh. The infrastructure provider (Google Cloud Platform) is contractually committed to handling data in line with international standard contractual clauses; we do not process your data in any jurisdiction without an equivalent legal protection regime to that of Bangladesh.
If we change cloud regions or providers, we will update this policy in line with Section 11.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated through the app or by email at least 14 days before they take effect.
12. Contact us
For any questions about this Privacy Policy or about how we handle your information, contact: