Privacy notice
This implementation minimizes collected data. A jurisdiction-specific notice and retention schedule must be approved before production.
Data processed
Account identity, contact details, sponsor relationship, authentication events, orders, reward records, and security audit signals are processed to operate and protect the service.
Security safeguards
Passwords are one-way hashed, multi-factor secrets are encrypted, payment references are fingerprinted rather than stored in plain text, sessions are encrypted, and audit IP addresses are stored as keyed hashes.
Data not collected by this build
The application does not collect card numbers, banking credentials, identity documents, or biometric data. Any future integration must be reviewed for least privilege and regulatory compliance.
Your choices
Members may request access or correction through support. Deletion may be restricted where transaction, fraud-prevention, tax, or other legal retention duties apply.
