Last updated: August 19, 2026
This policy is one of several. See the Legal & Compliance Center for every policy we publish, or go straight to Your Privacy Choices to access, correct or delete your data, our Cookie Policy, SMS Terms or Accessibility Statement.
IN N' OUT Market ("we," "us," "our"), part of the JRD Companies family, operates the convenience store, gas station, fresh-food kitchen and car wash at 743 Century Ave N, Maplewood, MN, and this website and mobile Rewards app. This policy explains what we collect and how we use it. By using this site or joining IN N' OUT Rewards, you agree to this policy.
Information We Collect
Account and contact data — When you join IN N' OUT Rewards, you provide your first and last name, email address, and mobile phone number. We assign you a unique member ID (a server-generated reference). We store your agreement to the program terms at the time you create your account.
Authentication data — We store a one-way HMAC-SHA-256 derivation of your 4-digit PIN, combined with a server-side secret. Your original PIN is never stored or shown to store staff. After sign-in, the app or browser receives a session token; in browsers, this is delivered as an HTTP-only session cookie that page scripts cannot read.
Contact verification — We use Twilio Verify to send one-time codes to your email address and mobile number when you create an account or change a contact method. We record whether each code was successfully verified. Message and data rates may apply. These account-service messages do not enroll you in marketing texts.
Points, tiers, and vouchers — We maintain a server-side ledger of your eligible purchase totals, points earned or refunded, tier status, and voucher issuance, application, and expiry. Balances are controlled entirely server-side and are never modified from client-provided amounts.
Clover purchase and refund history — Our rewards backend receives order and refund notifications from the Clover point-of-sale system via a verified webhook. When an order closes, we retrieve the authoritative order details (eligible item amounts, your phone number for member lookup, applicable taxes and discounts, and any refunds) from the Clover API using a server-side merchant token. We use this data solely to calculate and credit eligible rewards and to process refunds to your points balance. We do not retain full Clover order payloads beyond what is needed for rewards accounting.
Minnoco transfer info — The Minnoco ID or phone and point balance you self-report for a one-time in-store balance import, plus the transfer status, timestamps, and authenticated staff identity for in-store approval. No direct Minnoco or PatronPoints API connection is currently available; we rely on staff verification of the record.
First-party product interaction analytics (optional, consent-gated) — With your explicit opt-in, the IN N' OUT Rewards mobile app reports a limited set of named interaction events to our own first-party activity service (activity.innoutstores.com). Events are: app opened (with platform and app version), screen viewed (by screen name from a fixed approved list), member card viewed, offer viewed, reward viewed, and redemption started. No freeform text, location, contact information, or advertising identifier is sent. Analytics are stored against your member ID only when you have given consent and are retained for 90 days, after which they are automatically purged.
Necessary operational events (no consent required) — Our activity service records a fixed set of operational events that are necessary to run the Rewards program regardless of your analytics preference: account created, account claimed, login, logout, points earned or refunded, voucher issued or applied or expired, and account deleted. These are retained for 400 days and are used for fraud prevention, program integrity, and legal recordkeeping.
Web analytics (consent-gated) — When you accept analytics cookies on this website, our activity service records page visits, the referring site hostname, your general device class (mobile, tablet, or desktop), browser family, and operating system family derived from your browser's user-agent string. We do not retain the full user-agent string, raw IP addresses, or exact screen resolution. Instead, IP addresses are one-way hashed daily with a server-side key so that the hash cannot be reversed and rotates each day. If you accept analytics, pseudonymous daily-rotating visitor and session identifiers are also hashed. Web visit records are retained for 30 days. You can withdraw consent at any time in your browser using the link below.
Separately, Cloudflare may inject its own aggregate Web Analytics beacon on pages served through this domain. Cloudflare's analytics are aggregate-only, do not use cookies, and are governed by Cloudflare's privacy policy.
Messages you send us through contact forms, email, or text.
What We Do Not Collect
- No advertising identifier (IDFA, GAID, or equivalent) — we do not access or use any mobile advertising identifier.
- No cross-company tracking — we do not track you across other websites, apps, or organizations.
- No ad targeting or data brokerage — we do not use your data to serve third-party ads and do not sell or license it to data brokers.
- No raw IP address retention — IP addresses are hashed daily and the original is not stored.
- No arbitrary device properties — we collect only the named fields described above.
How We Use Your Information
- Operate the Rewards program — verify and identify your account, calculate and credit points from Clover purchase data, process approved Minnoco balance transfers, and issue or apply vouchers.
- Send required service messages — one-time verification codes for account creation and contact changes via Twilio Verify.
- Send marketing messages only where you have separately consented; you may opt out at any time.
- Generate internal business reports delivered to our authorized business email inbox (see below).
- Operate, secure, and improve our site and stores.
- Comply with the law and prevent fraud or abuse.
Internal Business Reports
Our activity service produces daily and weekly rewards reports and delivers them via Microsoft 365 to a single fixed business email address used by IN N' OUT Market management. These reports include each active member's name, email address, mobile phone number, member ID, current points balance, tier, eligible spend, points earned and redeemed, voucher activity summary, and date of last activity. Reports are used exclusively for store operations and compliance. Delivery payload records are retained for 7 days; delivery metadata is retained for 90 days. These reports are not shared with third parties and are not used for advertising.
Cookies & Local Storage
We use a secure, HTTP-only session cookie to keep you signed in to Rewards (page scripts cannot read this cookie). We use limited browser local storage for site preferences, safe retry tokens, and the consent state you select in the notice banner. When you first visit, a notice lets you Accept or Decline optional analytics. Clearing browser data signs you out on that device but does not delete your server-backed Rewards account or points. If you accepted analytics and wish to withdraw, use the link in the banner or visit your Rewards account settings.
How We Share Information
We do not sell your personal information. We share only what is necessary with service providers that help us operate the site and program:
- Cloudflare — hosts our Workers and Pages infrastructure; processes requests through its network.
- Clover (Fiserv) — our point-of-sale system; we retrieve order and refund data from their API using server credentials to calculate rewards.
- Twilio Verify — delivers one-time verification codes to your email and mobile number for account-service purposes only.
- Microsoft 365 — used to send internal business reports to our authorized business inbox.
Minnoco transfer information is used for the in-store bridge you request and is not shared with PatronPoints or Minnoco systems. We may also disclose information when required by law or to protect our rights, customers, or staff.
Data Retention
- Account and points data — retained while your account is active and as reasonably required for accounting, fraud prevention, and legal obligations.
- Operational events (login, points, vouchers, etc.) — 400 days.
- Optional product analytics (consent-gated mobile events) — 90 days.
- Web analytics (consent-gated visit records) — 30 days.
- Business report metadata — 90 days; report payload content — 7 days.
- Deleted accounts — contact data and PII are removed immediately on deletion (see below). An anonymized audit record is retained.
Account Deletion
You can delete your IN N' OUT Rewards account from within the mobile app or by contacting us. When you delete your account, we immediately remove your name, email, mobile phone, PIN derivation, and referral information from our active records and replace them with non-identifiable placeholders. Your active sessions are revoked and your analytics preferences are removed. An anonymized audit record (containing no contact information) is retained for legal and fraud-prevention purposes. Points and vouchers associated with a deleted account are forfeited and cannot be recovered.
Your Choices & Rights
- Access or correct your Rewards account name and contact info — update in the app or contact us.
- Delete your account — available in the IN N' OUT Rewards app under account settings, or by contacting us.
- Opt out of optional analytics — toggle product analytics off in the Rewards app settings, or decline/withdraw analytics consent in the site banner.
- Opt out of marketing — reply STOP to marketing texts, or use the unsubscribe link in marketing emails.
- Manage cookies — through your browser settings; note that clearing cookies will sign you out on that device.
If you are a Minnesota resident or otherwise have rights under applicable privacy law, you may exercise access, correction, deletion, or portability rights by contacting us at the address below.
Children
This site and the Rewards program are intended for adults. We do not knowingly collect information from children under 13.
Security
We use encrypted connections (TLS), access controls, revocable HTTP-only sessions, login-rate limiting, one-way PIN derivation with a server-side secret, and daily-rotating IP hashing to protect Rewards data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Changes to This Policy
We may update this policy from time to time. Changes take effect when posted here, and the "Last updated" date will change. Material changes to how we handle your data will be communicated through the Rewards app or this site.
Contact Us
Questions or requests? Call (651) 227-8820, email [email protected], or visit us at 743 Century Ave N, Maplewood, MN 55119.