Trust Center

Welcome to Our Trust Center

At Time Rewards, trust is the foundation of everything we do. Our Trust Center provides comprehensive information about how we protect your data, maintain security, ensure compliance, and operate with complete transparency.

We believe that earning and maintaining your trust requires ongoing commitment, clear communication, and the highest standards of security and privacy protection.

Our Commitment to Security

Data Protection Framework

Time Rewards employs a multi-layered security approach designed to protect your personal information and business data:

Encryption Standards:

  • Data in Transit: TLS 1.3 encryption for all data transmission
  • Data at Rest: AES-256 encryption for stored data
  • Database Security: End-to-end encryption with rotating keys
  • API Security: OAuth 2.0 and API key authentication

Infrastructure Security:

  • Cloud Platform: Enterprise-grade AWS infrastructure
  • Network Security: Firewalls, intrusion detection, and DDoS protection
  • Access Controls: Multi-factor authentication and role-based permissions
  • Monitoring: 24/7 security monitoring and incident response

Security Certifications and Audits

We maintain industry-leading security certifications and undergo regular third-party audits:

Current Certifications:

  • SOC 2 Type II – Annual third-party security audit
  • ISO 27001 – Information security management certification
  • PCI DSS Level 1 – Payment card industry compliance
  • GDPR Compliance – European data protection regulation adherence

Audit Schedule:

  • Annual SOC 2 Type II audits by independent certified public accountants
  • Quarterly penetration testing by certified ethical hackers
  • Monthly vulnerability assessments and security reviews
  • Continuous compliance monitoring and reporting

Incident Response and Security Monitoring

24/7 Security Operations Center:

  • Real-time threat detection and response
  • Automated security alerts and incident escalation
  • Forensic analysis and threat intelligence
  • Coordinated response with law enforcement when necessary

Incident Response Process:

  1. Detection: Automated and manual threat identification
  2. Assessment: Impact analysis and severity classification
  3. Containment: Immediate threat isolation and mitigation
  4. Investigation: Root cause analysis and evidence collection
  5. Recovery: System restoration and security enhancement
  6. Communication: Transparent user and stakeholder notification

Privacy and Data Protection

Privacy by Design

Time Rewards integrates privacy protection into every aspect of our operations:

Data Minimization:

  • Collect only necessary personal information
  • Regular data retention review and purging
  • Purpose limitation for data processing
  • Automated data lifecycle management

User Control and Transparency:

  • Granular privacy settings and preferences
  • Easy-to-understand privacy policies
  • Self-service data access and deletion tools
  • Regular privacy impact assessments

Global Privacy Compliance

GDPR (General Data Protection Regulation):

  • Lawful basis for all data processing activities
  • Data Protection Officer (DPO) oversight
  • Privacy impact assessments for high-risk processing
  • Cross-border data transfer safeguards

CCPA (California Consumer Privacy Act):

  • Consumer rights implementation and support
  • “Do Not Sell My Personal Information” compliance
  • Transparent data sharing disclosures
  • Authorized agent verification procedures

Additional Regulations:

  • LGPD (Brazil) – Lei Geral de Proteção de Dados compliance
  • PIPEDA (Canada) – Personal Information Protection Act adherence
  • COPPA (USA) – Children’s Online Privacy Protection compliance
  • PECR (UK) – Privacy and Electronic Communications Regulations

Data Processing and Storage

Data Centers and Infrastructure:

  • Primary: AWS US-East (Virginia) – SOC 1/2/3 certified
  • Backup: AWS US-West (Oregon) – Geographic redundancy
  • International: EU data residency options available
  • Disaster Recovery: 99.9% uptime SLA with automated failover

Data Retention Policies:

  • Account Data: Retained while account is active + 7 years
  • Transaction Data: Retained for 7 years for compliance purposes
  • Marketing Data: Retained until consent withdrawal
  • Log Data: Retained for 90 days for security monitoring

Compliance and Governance

Regulatory Compliance Framework

Time Rewards maintains compliance with applicable laws and regulations across all jurisdictions where we operate:

Financial Services Compliance:

  • PCI DSS: Payment card industry data security standards
  • SOX: Sarbanes-Oxley financial reporting requirements
  • AML/KYC: Anti-money laundering and know your customer procedures
  • FFIEC: Federal Financial Institutions Examination Council guidelines

International Trade Compliance:

  • OFAC: Office of Foreign Assets Control sanctions screening
  • Export Administration Regulations (EAR) compliance
  • ITAR: International Traffic in Arms Regulations adherence
  • Denied Parties List screening and monitoring

Third-Party Risk Management

Vendor Security Assessment:

  • Comprehensive security questionnaires for all vendors
  • Annual risk assessments and compliance reviews
  • Contractual security requirements and SLAs
  • Continuous monitoring of third-party security posture

Sub-processor Management:

  • GDPR Article 28 compliant data processing agreements
  • Regular security audits of sub-processors
  • Geographic data processing restrictions
  • Transparent sub-processor disclosure and notification

Transparency and Reporting

Transparency Reports

We publish regular transparency reports to provide insight into:

  • Security Incidents: Summary of security events and responses
  • Data Requests: Government and law enforcement data requests
  • Compliance Updates: Changes to regulations and our compliance posture
  • System Performance: Uptime, availability, and performance metrics

External Audits and Certifications

Available Documentation:

  • SOC 2 Type II reports (available under NDA)
  • ISO 27001 certification documents
  • Penetration testing executive summaries
  • Compliance attestation letters

Bug Bounty Program

We operate a responsible disclosure program that rewards security researchers for identifying vulnerabilities:

Program Details:

  • Scope: All Time Rewards web and mobile applications
  • Rewards: $100 – $10,000 based on severity and impact
  • Response Time: Initial response within 24 hours
  • Resolution: 90-day coordinated disclosure timeline

Enterprise Security Features

Advanced Security Controls

For Enterprise Customers:

  • Single Sign-On (SSO): SAML 2.0 and OAuth integration
  • Multi-Factor Authentication: SMS, app-based, and hardware tokens
  • Role-Based Access Control: Granular permission management
  • API Security: Rate limiting, authentication, and monitoring

Administrative Controls:

  • Audit Logs: Comprehensive activity logging and reporting
  • User Provisioning: Automated onboarding and offboarding
  • Session Management: Configurable timeout and concurrent session limits
  • IP Restrictions: Whitelist-based access controls

Business Continuity

Disaster Recovery:

  • Recovery Time Objective (RTO): 4 hours maximum
  • Recovery Point Objective (RPO): 1 hour maximum data loss
  • Geographic Redundancy: Multi-region backup and failover
  • Business Continuity Plan: Tested quarterly with stakeholder involvement

Service Level Agreements:

  • Uptime: 99.9% availability guarantee
  • Response Time: < 200ms average API response time
  • Support: 24/7 enterprise support with dedicated account management
  • Maintenance Windows: Scheduled during low-usage periods with advance notice

Contact Our Security Team

Security Inquiries

For security-related questions, vulnerability reports, or enterprise security requirements:

Security Team Contact: Email: security@timerewards.com Phone: 1-800-631-1365 (Ext 144) PGP Key: Available upon request for encrypted communications

General Support: Email: support@timerewards.com Phone: 1-800-631-1365 (Ext 144) Business Hours: Monday – Friday, 9:00 AM – 6:00 PM CST

Corporate Address: Time Rewards Security Office 9600 Great Hills Trail Suite 150W Austin, TX 78759 United States

Data Protection Officer

For privacy-related inquiries, data subject requests, or GDPR compliance questions:

Email: support@timerewards.com
Response Time: 72 hours for initial response Languages: English, Spanish, French, German

Continuous Improvement

Security Enhancement Program

We continuously invest in improving our security posture through:

  • Regular Security Training: All employees receive quarterly security awareness training
  • Threat Intelligence: Subscription to leading threat intelligence services
  • Security Research: Investment in emerging security technologies and practices
  • Industry Collaboration: Active participation in security industry groups and forums

Feedback and Suggestions

We welcome feedback on our security and privacy practices:

  • Security Advisory Board: Quarterly meetings with external security experts
  • Customer Feedback: Regular surveys and feedback collection
  • Employee Reporting: Internal security incident and improvement reporting
  • Industry Benchmarking: Annual comparison with industry security standards

Recent Updates and Announcements

June 2025 Security Enhancements

  • Implemented advanced threat detection using machine learning
  • Enhanced multi-factor authentication with biometric options
  • Upgraded encryption standards to post-quantum cryptography preparation
  • Expanded security monitoring to include supply chain risk assessment

Upcoming Initiatives

  • Q3 2025: ISO 27017 cloud security certification
  • Q4 2025: SOC 3 public report publication
  • 2026: Implementation of zero-trust security architecture
  • 2026: Enhanced privacy controls with automated data discovery

Time Rewards is committed to maintaining the highest standards of security, privacy, and compliance. Our Trust Center reflects our ongoing dedication to transparency and continuous improvement in protecting our users and their data.