This guide covers how to set a strong password and how two-factor authentication works on RewardPay.
Your RewardPay account is the gateway to your business payments, so keeping it secure matters. Alongside our own bank-grade security, there are a few simple things you can do to protect your account.
Setting a strong password
When you create your RewardPay account, choose a password that is unique to RewardPay and not reused from any other site. If a password you use elsewhere is ever exposed in a data breach, reusing it puts your RewardPay account at risk too.
A strong password is long, hard to guess, and not based on personal details like your business name, birthday or the word “password”. A passphrase made of several unrelated words is both easier to remember and harder to crack than a short, complex string.
We recommend storing your password somewhere safe, such as a reputable password manager, rather than writing it down or saving it in your browser on a shared device. If you ever suspect your password has been compromised, change it straight away and contact our support team.
Two-factor authentication
Two-factor authentication, often shortened to 2FA, adds a second layer of protection on top of your password. Even if someone were to obtain your password, they would still need access to your second factor to authorise activity on your account.
Two-factor authentication is required for all users on RewardPay. Rather than relying on your password alone, we use it to confirm it is really you at the point of certain sensitive actions on your account. Because your account handles business payments, this extra check helps keep your funds and your account details protected.
RewardPay supports two methods for your second factor. You can use an authenticator app, such as Google Authenticator, which generates a time-based code on your device. Alternatively, you can receive a code by SMS to your registered mobile number. When a second factor is required, you enter the code to confirm the action.
Of the two, an authenticator app is generally the more secure option, as app-based codes are not exposed to risks associated with mobile networks. It is also the better choice if you travel, since an authenticator app generates codes directly on your device and works even when you cannot receive an SMS, such as when you are overseas or without mobile reception.
If you lose access to your second factor
If you change your mobile number or lose access to your authenticator app, you may not be able to complete two-factor authentication when a second factor is required. If this happens, contact our support team so we can help you regain access securely. For your protection, we will need to verify your identity before making any changes.
A few more habits that keep your account safe
Log out when you have finished using your RewardPay account, especially on shared or public devices. Keep your registered email and mobile number up to date, since these are how we reach you and how your SMS codes are delivered. Be alert to phishing: RewardPay will never ask you for your password, by email, phone or text. If anyone asks for your password, or a message claims to be from us and something feels off, treat it as suspicious and contact us directly.
Questions
If you have any questions about securing your account or you think your account may have been compromised, contact our support team straight away at support@rewardpay.co.nz.