Rewards Store Privacy Notice (North America)

Miltenyi Rewards Store Program Documents

Effective Date: February 2, 2026
Last Updated: August 17, 2026
Program Sponsor: Miltenyi Biotec Inc. ("Miltenyi," "we," "us")
Program Name: Miltenyi Rewards Store ("Program")

3) Rewards Store Privacy Notice (North America)

3.1 What we collect

We collect information needed to operate the Rewards Store and administer the Program, including:

Account information: Your name, email address, job title, institution or company, lab department, and other profile information you provide.

Authentication information: You create an account using an email address and password. Rewards Store passwords are stored using a one-way salted PBKDF2-SHA-256 password hash together with the salt, iteration count, and algorithm metadata in a restricted credentials record. Usable plaintext passwords are not retained after registration or password update, are not displayed back to users, and are not included in rewards transaction records.

Shipping information: A shipping destination address you provide when needed to fulfill a physical reward redemption.

Purchase and verification information: Delivery-note or webshop-order identifiers, product or SKU details, eligible purchase values, submission status, supporting images or PDFs, and administrative review details used to verify eligibility and prevent duplicates.

Program activity: Points balances, earning and adjustment history, redemption records, reward orders, campaign activity, training or engagement requests, support interactions, versioned affirmative Program-consent records, and the member's current optional analytics preference.

Usage and technical information: Page and feature activity, product/cart/checkout events, outbound-link activity, and technical request information used to operate and improve the Rewards Store.

3.2 Why we use purchase and program information

We use this information to:

  • validate eligible purchases and program eligibility,
  • calculate and administer rewards under Program rules,
  • prevent duplicate submissions, fraud, and abuse,
  • process physical reward redemptions and fulfillment,
  • maintain rewards transaction and audit records,
  • provide customer service and resolve disputes,
  • understand how the Rewards Store is used and improve the experience.

3.3 Uploaded delivery-note and order documents

For new manual-review delivery-note submissions, uploaded pages are stored in private Base44 storage. After submission, authorized Rewards Store administrators access those private documents through short-lived signed links rather than permanent public application links.

Some documents uploaded before the private-storage transition remain in legacy Base44-hosted storage locations. The Rewards Store restricts access to the associated submission records through the application to authorized administrators. We are retaining those existing storage objects until a supported, verifiable physical-deletion mechanism is available rather than creating replacement copies that would leave the originals behind.

When an automated document-processing workflow is enabled, document images may also be sent to the Program's document-processing infrastructure for verification.

Please upload only information necessary to validate an eligible Miltenyi purchase. Do not upload payment card numbers, bank account information, Social Security numbers, protected health information, medical records, or other sensitive personal information that is not required for verification.

3.4 Retention and deletion

We retain account and Program information for the period reasonably needed for the purposes described in this notice, subject to applicable legal, accounting, fraud-prevention, fulfillment, and program-integrity requirements.

When you delete your Rewards Store account, the deletion workflow removes sign-in credentials and active custom sessions, deletes the customer profile and its contact, shipping, and cart data, and removes or de-identifies account links in retained rewards and audit records where appropriate.

Application references to uploaded delivery-note documents are removed during account deletion. Where the storage platform does not currently expose a supported and verifiable physical-delete operation, the underlying file reference is placed into a restricted cleanup queue. We do not treat that storage cleanup as completed until deletion can be verified.

If a physical reward order is already processing when an account is deleted, the minimum fulfillment snapshot needed to complete that order may be retained until the order leaves the processing state. That fulfillment snapshot is then purged by the deletion workflow.

De-identified rewards, transaction, anti-fraud, and audit records may be retained where reasonably necessary to preserve Program integrity or satisfy applicable obligations. Internal usage analytics records directly linked to the deleted account and the account's current optional analytics preference are removed by the account-deletion workflow.

3.5 Rewards Program integrity

Rewards points are calculated by Rewards Store backend services based on eligible activity and Program rules. Customers may not directly modify their own points balance, approval status, transaction history, or rewards ledger.

Each eligible document or webshop-order identifier may be credited only as permitted by Program rules. Duplicate submissions may be automatically blocked, rejected, or flagged for review. Authorized Rewards Store administrators may review submissions, approve or reject points, process redemptions, and support fulfillment.

3.6 Optional analytics and country-level availability checks

After a signed-in member reaches the Rewards Store Home experience, we ask whether the member wants to allow optional analytics. When a signup promotion includes a bonus presentation, that bonus is shown before the analytics choice; the optional analytics choice is then shown before the one-time spotlight tour.

If the member selects Accept analytics, the Rewards Store may load Google Analytics and record usage events such as product views, cart activity, checkout activity, and completed reward-redemption events. Google Analytics may use analytics cookies after acceptance. Analytics events can include product or reward identifiers, names, categories, point values, and transaction identifiers. Advertising storage, advertising user-data signals, and advertising personalization signals are disabled for this Rewards Store analytics configuration.

If the member selects Decline analytics before Google Analytics has loaded, the Google Analytics tag is not loaded. If the member changes an earlier acceptance to Decline, collection is disabled immediately and Rewards Store-accessible Google Analytics cookies are cleared. Optional internal behavioral analytics are not recorded while the preference is declined. Declining analytics does not affect account access, points, earning, checkout, rewards, or other Rewards Store functionality. Members can change this choice later from Privacy Choices in the Rewards Store.

When optional analytics are accepted, the Rewards Store may also maintain internal page-view, news-view, and outbound-click records for selected pages. These records are created only after a validated custom member session and an accepted analytics preference are confirmed server-side. They may include the member's account email together with page type, page name, page path, article information, and outbound destination where applicable. Browser-supplied identity fields are not trusted for these records.

Before this optional choice control was introduced, the Rewards Store collected certain Google and internal usage analytics as described in earlier versions of this notice. Going forward, optional behavioral analytics are collected only after the member accepts them. Account deletion removes linked internal usage analytics and the stored analytics preference under the Rewards Store deletion workflow.

The country-level availability check is separate from optional analytics. On ordinary member-app entry, the Rewards Store uses ipapi.co to determine the visitor's country from network/IP information so the Program can apply its U.S./Canada availability rule. Public legal, privacy, financial-incentive, and account-deletion pages bypass this geo check.

3.7 Service providers and recipients

We use service providers to operate specific parts of the Program. Depending on your activity, information may be processed by:

  • Base44 for application infrastructure, database services, backend functions, and file storage,
  • Google Analytics for optional usage analytics only after the member accepts analytics,
  • ipapi.co for country-level availability checks on ordinary member-app entry,
  • AWS-hosted document-processing infrastructure when an automated document scan workflow is used,
  • Resend for transactional email delivery,
  • EPS for physical reward fulfillment when a reward order needs to be shipped.

We disclose information to these providers only as needed for the relevant Program function and subject to applicable contractual, confidentiality, security, and legal requirements.

3.8 Data security

We use administrative, technical, and organizational safeguards designed to protect customer information. Current controls include restricted entity access, server-side identity validation for sensitive operations, one-way password hashing for current and migrated credentials, opaque custom-session tokens whose hashes are stored server-side, private storage for new manual-review delivery-note uploads, short-lived signed administrator file links, and server-side reward calculations.

No system can guarantee absolute security. Keep your credentials confidential and contact us promptly if you believe your account may have been compromised.

3.9 Data minimization and AI processing

We design the Rewards Store to retain structured information needed for verification, rewards administration, fulfillment, support, and program integrity rather than unnecessary document content. Automated document-processing functionality may analyze uploaded documents when that workflow is enabled.

Production customer information is not intentionally submitted by the Rewards Store for the purpose of training a general-purpose AI model. Service-provider processing remains subject to the applicable service configuration and contractual terms.

3.10 No sale or cross-context behavioral advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Optional analytics are used to measure and improve the Rewards Store experience only after the member accepts them; advertising and cross-site personalization signals are disabled in the Rewards Store Google Analytics configuration.

3.11 Email notifications

The Rewards Store may send transactional emails related to account activity, submission status, points awards, reward redemptions, fulfillment updates, training requests, and customer support. Transactional messages may be delivered through Resend from a Rewards Store no-reply address.

3.12 Account deletion and privacy requests

Members can initiate account deletion from the Profile section while signed in. We also provide a public credential-verified account deletion page, which remains available independently of the member application's geo gate and maintenance state.

For other privacy requests, corrections, or questions, contact us using the information below. We may need to verify your identity before acting on a request.

3.13 California and Canada considerations

California: This Program includes a Notice of Financial Incentive and provides a method to withdraw from the Program.

Canada: We apply privacy principles that emphasize limiting collection to identified purposes, appropriate safeguards, and limiting retention to the period reasonably needed for those purposes.

3.14 Contact

For privacy, Program, verification, or withdrawal questions:
orderdesk@miltenyi.com

Mail: 1201 Clopper Rd, Gaithersburg, MD 20878