Pikt credit card rewards
Your best card before you pay online.
Pikt estimates which card in your wallet is likely to earn the most. Issuers decide. You choose the card and pay as usual.
Pikt credit card rewards
Your best card before you pay online.
Pikt estimates which card in your wallet is likely to earn the most. Issuers decide. You choose the card and pay as usual.
Security
Add cards by name — never card numbers. Pikt recommends which card to use and never pays for you. Bank linking is optional and read-only when you turn it on.
Pick the cards you carry from the catalog. We store which products you selected — never full card numbers, CVVs, or PINs.
Pikt names the best card in your wallet and shows the dollar difference. You always pay with your own card. We never issue a card or move your money.
Card Check and Pikt Checkout work without a bank link. If you connect a bank later, access is read-only for bills and spend insights — we cannot move, send, or withdraw money.
You authorize access through Plaid or your bank. Pikt receives account data and an access token, not your bank password. An access token lets Pikt retrieve the data you authorize.
You authorize access through Quiltt and its bank connection providers. Pikt receives account data and connection identifiers, not your bank password.
Pikt uses HTTPS to protect data sent between your browser and our service. Stored Plaid access tokens and dates of birth use AES-256-GCM encryption. These controls do not mean that Pikt has completed a security certification.
Disconnect in Settings → Cards & bank to stop new imports. Pikt revokes Plaid access and removes its Quiltt connection. Removing a Quiltt connection does not revoke access at the provider; contact support for help with that step. Previously imported history stays until deleted or its retention period ends.
Not yet completed: our own SOC 2 audit and independent penetration test. Both are planned.
We store
We never store
There is no card vault
What the extension can access
How we get paid
What does not change
If a security incident affects your data, we will notify affected users as required by applicable law and explain what happened and what to do next. To report a security concern, email [email protected].
Penetration testing
Independent third-party testing is planned, not yet completed. We plan annual tests ahead of releases that touch authentication, payments, or bank connectivity. Summary findings will be available to qualified partners under NDA once testing completes.
Data retention
Website deletion requests have a 14-day recovery period after email confirmation. Permanent deletion follows within 90 days unless a legal hold applies. In-app deletion on iOS or Android starts permanent deletion immediately, with no recovery period. Some audit and deletion-proof records remain. Analytics events carry an account identifier and stay for up to 12 months unless you request earlier removal. See the Privacy Policy retention details.
CCPA requests
Access and deletion requests are handled within 45 days at [email protected]. A formal CCPA program review is underway. The optional Pikt Personal program and exactly what it collects are covered in our Privacy Policy.
Pikt has not completed its own SOC 2 audit. Our providers publish their own security information: hosting (Vercel (opens in a new tab)), our database (Railway (opens in a new tab)), authentication (Clerk (opens in a new tab)), and bank connections (Quiltt and Plaid). Provider reports cover their own systems. They do not certify Pikt. See each provider's trust center for current information.
Request a security report
Evaluating Pikt for your organization? Request our security documentation. Penetration test summaries will be shared once testing completes.
Pikt is operated by Pikt Rewards. Have a security question or want to report a concern? Email [email protected].