Incentra Systems is committed to responsible stewardship of consumer data. As a digital wallet platform operating in regulated markets, we recognize that consumer trust is foundational to our mission. Our privacy practices are designed to meet or exceed the requirements of the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR), and we apply these standards across all markets we serve, not just those where such laws are strictly required.
Incentra collects only the personal information necessary to operate our container deposit redemption platform. This includes:
Consistent with GDPR principles of data minimization and purpose limitation, we do not collect personal data beyond what is required for the specific, legitimate purposes for which it was gathered. We do not collect sensitive personal information beyond what is required for identity verification and regulatory compliance, and we do not sell consumer personal information to third parties.
Consistent with CCPA and GDPR principles, Incentra provides consumers with meaningful control over their personal data. Consumers using the Incentra platform have the right to:
Where GDPR applies, consumers also have the right to data portability, the right to restrict processing, and the right to object to processing based on legitimate interests. We provide clear, accessible mechanisms, both in-app and through our support channels, for consumers to exercise these rights.
In markets where GDPR applies, Incentra processes personal data only where a lawful basis exists. Depending on the nature of the activity, this may include the performance of a contract with the consumer, compliance with a legal obligation, or our legitimate interests in operating a secure and effective platform, provided those interests are not overridden by the individual's rights and freedoms. Where we rely on consent as a legal basis, we ensure that consent is freely given, specific, informed, and revocable at any time.
Incentra employs technical and organizational safeguards appropriate to the nature of the data we handle. Our security practices include:
We apply a data minimization philosophy: collecting only what is needed, retaining it only as long as necessary, and securely disposing of it when it is no longer required. These practices align with both CCPA requirements and the GDPR's principle of integrity and confidentiality.
Where Incentra shares consumer data with third parties, including grocery retail partners, material processing operators, or technology vendors, we do so only to the extent necessary to deliver our service. All third-party data relationships are governed by contractual agreements that impose privacy and security obligations consistent with our own standards. Where GDPR applies, these agreements include appropriate data processing terms as required by applicable law. We do not engage in the sale of consumer personal information, and any data sharing for operational purposes is disclosed clearly in our consumer-facing privacy notice.
Incentra maintains a formal privacy notice that describes our data practices in plain language. We are committed to keeping this notice current as our platform and regulatory obligations evolve. Our compliance program accounts for the requirements of the CCPA and its amendments under the California Privacy Rights Act (CPRA), the GDPR, as well as applicable data protection requirements in the Northeast states where we operate. As we expand into new markets, we conduct privacy impact assessments to ensure our practices remain aligned with applicable law and consumer expectations.
We welcome inquiries from partners, clients, and regulators regarding our privacy practices and are prepared to provide additional documentation upon request.
For questions regarding Incentra's privacy practices, please contact us directly through our official channels.