Privacy Policy
FashionPass Rewards
Effective date: July 22, 2026
This Privacy Policy explains how we collect, use, share, and protect your personal information when you join and use FashionPass Rewards, our free loyalty program for FashionPass's participating retail stores in Jordan (currently including GO Sport, Puma, Geox, Calvin Klein, and Tommy Hilfiger locations operated by us in Jordan).
Please read this alongside our Terms of Service. By creating a FashionPass Rewards account, you agree to the practices described here.
Who We Are
FashionPass Rewards is operated by No Limits For General Trading LLC ("FashionPass," "we," "us," or "our"), located at Meethaq Tower, Princess Basma Street, Abdoun, Amman 11191, Jordan. We are responsible for the personal information processed through the loyalty program.
If you have any questions about this policy or your information, contact us at info@nolimitsjo.com or reach our privacy contact at info@nolimitsjo.com (mark your message "Privacy").
The Information We Collect
Information you give us
When you register and use your account, we collect:
- Your name (full name).
- Your username, which becomes your public identity in the program.
- Your email address. This is required. Note: we do not currently send a verification email, so the address on file may be unverified.
- Your phone number. This is optional and may be left blank. If you provide it, it is not verified.
- Your password, which we store only in a securely hashed form. We never store or see your password in plain text.
- Community content you choose to create, such as posts (text and optional images), product reviews (a rating, a comment, and the product name), and any abuse reports you submit (which include the reason you provide).
- Messages you add to points transfers. If you send points to another member, any short message you include is stored with that transfer.
We also assign you a customer code at sign-up. This is a unique code we generate and place in your member QR card so staff can identify you when you make a purchase in store.
When you register, we set a default profile image and a default bio on your account. You can change your profile details — including your name, bio, profile image, and phone number — at any time from the app.
Loyalty and purchase information
As you use the program, we collect and store:
- Your points and loyalty status, including your current points balance, lifetime points, tier, tier progress, total amount spent (in JOD), your join date, and whether you were referred by another member.
- A record of every points event in your account ledger, including purchases, transfers, welcome bonuses, and point expiry. Each record can include the points amount, a description, the date, and a related receipt or document reference.
- Detailed in-store purchase information. When you make a qualifying purchase, we store the purchase details linked to your account, including the store/location, the staff member's identifier, the amount and currency (JOD), and the individual items you bought (product name, barcode, item code, quantity, unit price, and line total).
Information collected automatically
- IP address. We automatically record the IP address you used when you registered. We use this to help prevent abuse of our one-time welcome bonus (see "How and Why We Use Your Information"). For IPv6 addresses, we store only a shortened version of the address. Your IP address may also appear in our security and audit logs and is used temporarily to limit the rate of requests to sensitive parts of the service. Our administrators can view the sign-up IP address associated with member accounts.
- Security and audit logs. We keep logs of security-relevant and money-relevant actions, such as logins, failed login attempts, points transfers, purchases, welcome-bonus limits, and content moderation actions. These logs can include an IP address and a username or account identifier.
Cookies
We use a small number of first-party cookies that are necessary to operate the service securely. We do not use third-party cookies, advertising cookies, or analytics/tracking cookies.
sz_gate— Confirms your browser has passed our site-access gate. Lasts 7 days.sz_session— Keeps you securely signed in to your member or admin session. Lasts 24 hours (default).
Both cookies are set as HttpOnly (they cannot be read by scripts in your browser), SameSite=Lax, and Secure when you connect over HTTPS. We do not store your login token in your browser's local storage.
How and Why We Use Your Information
We use your information to:
- Run the loyalty program and your account — create and maintain your membership, manage your points and tier, and identify you at checkout using your customer code/QR card.
- Award and redeem points for in-store purchases — credit points for qualifying purchases, record the purchase details described above, and process redemptions and transfers.
- Prevent fraud and abuse — use your sign-up IP address to limit how many accounts can claim the one-time welcome bonus from the same source, limit the rate of requests to sensitive endpoints, cap repeated incoming points transfers, and investigate suspicious activity through our audit logs.
- Keep your account secure — authenticate you, manage your sessions, and handle password resets.
- Provide community features — display your posts and reviews to other members, record which posts you have liked, and let you report content you believe breaks the rules.
- Send you notifications — deliver in-program messages tied to your account (for example, about points or account activity).
Notifications and Your Preferences
We send only in-program notifications tied to your account, such as updates about points or account activity. We do not send third-party marketing. You can turn these notifications on or off at any time from the Settings page in your account, or contact us at info@nolimitsjo.com and we will adjust your preferences for you.
Automated Decisions
Some features of the program operate automatically, without a manual review of each case. In particular:
- Membership tiers and tier progress are calculated automatically from your spending over the last 12 months.
- Anti-fraud limits are applied automatically — for example, a cap on how many accounts can claim the one-time welcome bonus from the same network/IP address, rate limits on sensitive actions, and caps on repeated incoming points transfers.
These automated processes help us run the program fairly and prevent abuse. If you believe an automated decision has affected you unfairly, you can contact us at info@nolimitsjo.com and we will look into it.
Cookies
As described above, we use only the essential first-party cookies sz_gate and sz_session to keep the service working and to keep you securely signed in. Because these cookies are necessary for the service to function, blocking them in your browser may prevent you from signing in or using the program. We do not use cookies for advertising, third-party tracking, or analytics.
Sharing and Third Parties
We do not sell your personal information.
We share information only in the following limited ways:
- Point-of-sale and SAP Business One integration. Our in-store till and ERP system exchange information with the loyalty program so that purchases earn points. When you make a purchase, the point-of-sale system sends your scanned customer code, the store, the currency (JOD), and the purchase line items (such as barcode, item code, quantity, and unit price) to your account, where they are recorded in your transaction ledger. The integration also pulls product catalog information (item codes, names, barcodes, and prices) into our system; this product sync does not involve your personal information. This is our own retail system, not an outside company.
- Service providers. Where we use providers to help operate the service, they may process information on our behalf and under our instructions. Where an in-app offer does not include an uploaded image, a generic placeholder image may be loaded from an external image host.
- Legal requirements. We may disclose information where we are required to do so by law, regulation, legal process, or a valid request from a competent authority, or where necessary to protect our rights, our members, or the security of the program.
We do not currently use any payment processor, advertising network, analytics service, or external email/SMS provider within the program.
International Data Transfers
The loyalty program's data is processed and hosted in Germany (Hetzner data center). Some elements of the service may load content from outside that location — for example, a generic placeholder image shown for some in-app offers may be loaded from a third-party image host, which means a request to that host is made when that image is displayed.
Where any processing of your information involves a transfer across borders, we handle it in line with applicable law and take steps to ensure your information remains protected.
Data Retention
We keep your account, points, and transaction records for as long as your account is active so that we can operate the program. In particular:
- Your points and transaction ledger (including detailed in-store purchase records, item-level data, and points transfers) are retained while your account exists, and may be retained afterwards where required by law or for fraud-prevention, accounting, or security purposes. These records are kept even after points expire.
- Community posts, product reviews, abuse reports, notifications, and your sign-up IP address are retained unless removed.
- Points expire after 12 months with no earning or redeeming activity on your account — the whole balance expires at once. Expiry removes the points from your usable balance but does not delete the underlying transaction records.
- Security and audit logs are retained where required by law or for fraud prevention and security purposes.
- Sessions and tokens expire automatically — your sign-in session token expires after 24 hours (default) and your site-access cookie after 7 days. Logging out or resetting your password invalidates previously issued tokens.
Deleting or correcting your data. You can delete your account yourself at any time from the Settings screen in the app (you will be asked to confirm with your password). Deletion permanently removes your personal details — your name, email address, phone number, username, bio, profile image, and sign-up IP address — from your account, revokes all sign-in sessions, and removes your registered notification devices. You can also update your name, bio, profile image, and phone number yourself from the app at any time, or contact us at info@nolimitsjo.com for anything else. Please note that certain records — in particular the points/transaction ledger and our security/audit logs — are retained where required by law or for fraud prevention, so we may not be able to erase those records in full.
Administrators can remove individual community posts or reviews (and their related reports) through content moderation.
Your Rights and How to Exercise Them
Subject to applicable Jordanian law, you may have the right to:
- Ask what personal information we hold about you and request a copy.
- Ask us to correct information that is inaccurate or incomplete.
- Ask us to delete your account or personal information.
- Object to or ask us to restrict certain processing.
- Withdraw any consent you have given.
You can handle the most common actions yourself in the app: you can edit your profile details (name, bio, profile image, and phone number) and delete your account from the Settings screen. For other requests, contact us and we will act on them to the extent technically and legally possible; certain records (such as the points/transaction ledger and security/audit logs) may be retained where required by law or for fraud prevention.
To exercise any of these rights, contact us at info@nolimitsjo.com or info@nolimitsjo.com (mark your message "Privacy"). We may need to verify your identity before acting on your request. The exact rights available to you, and the time we have to respond, are determined by applicable law under Jordan.
How We Protect Your Information
We use a range of technical and organizational measures to protect your information, including:
- Password protection — passwords are stored using strong one-way hashing and are never returned to anyone, including you.
- Encryption in transit — the service is HTTPS-only, with modern TLS, automatic redirection from HTTP to HTTPS, and HSTS.
- Secure cookies — authentication cookies are HttpOnly, SameSite=Lax, and Secure over HTTPS, so they cannot be read by browser scripts.
- Access controls — sign-in tokens can be revoked, sensitive actions are restricted to authorized staff or systems, and we use safeguards to prevent one member from accessing another member's data.
- A site-access gate that sits in front of the entire service.
- Rate limiting and request limits to reduce automated abuse.
- Audit logging of security- and money-relevant actions.
- Input protection for stored content, including length limits and restrictions on the types of links and images that can be stored.
No method of transmission or storage is ever completely secure, so while we work hard to protect your information, we cannot guarantee absolute security.
Children
FashionPass Rewards is intended for adults. You must be at least 16 years old to join. The program is not directed at children below that age, and we do not knowingly collect personal information from them. If you believe a child has registered, please contact us so we can address it.
Governing Language
This Privacy Policy may be made available in more than one language. If it is translated, and there is any conflict or inconsistency between versions, the English version will prevail.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" above and, where appropriate, let you know through the program. Your continued use of FashionPass Rewards after an update means you accept the revised policy.
How to Contact Us or Raise a Complaint
If you have questions, requests, or concerns about your privacy, contact us at:
- No Limits For General Trading LLC
- Email: info@nolimitsjo.com
- Privacy contact: info@nolimitsjo.com (mark your message "Privacy")
- Address: Meethaq Tower, Princess Basma Street, Abdoun, Amman 11191, Jordan
If you are not satisfied with our response, you may have the right to lodge a complaint with the competent data protection authority in Jordan under Jordan.