Technical schedule · effective 15 July 2026
Merchant data-processing schedule.
The customer and merchant information handled while Nabaperks provides a venue subscription.
Data handling
Nº DP-2026-07Processing scope
This technical schedule describes the information handled while Nabaperks provides a venue subscription. It does not assign controller, processor, or joint-controller roles that are not established by the repository. Processing supports merchant and customer authentication, venue memberships, accepted loyalty terms, stamps, rewards, scans, referrals, communications, subscriptions, fraud controls, support, analytics, retention, and audit records.
People and data categories
Affected people may include customers, prospective reward recipients, merchant owners and users, administrators, and support users. Customer data may include phone identity, phone country and last four digits, name, date of birth, email, verification state, memberships, accepted terms, stamps, rewards, referrals, consent, notifications, push subscriptions, fraud evidence, sessions, and support history. Merchant data may include authentication, venue and address details, coordinates, card and reward settings, QR records, billing references, product events, and audit records.
Processing operations
The application collects, validates, encrypts, hashes, stores, queries, displays, transmits, updates, exports, suppresses, revokes, anonymises, and deletes information according to the relevant product flow. Server state is authoritative; browser storage is used only for authentication, journey continuity, security, convenience, offline assets, and optional notifications.
Access and venue scoping
Customer loyalty information is linked to the relevant merchant and membership. Authenticated merchant tools use venue-scoped database operations. Trusted server jobs use privileged credentials only in server-side code. Nabaperks administrative access supports privacy requests, fraud review, billing support, retention jobs, and auditable corrections.
Implemented security measures
Implemented controls include encrypted customer phone values, keyed digests for identity and invitation matching, signed and revocable customer sessions, HttpOnly verification and session cookies, Supabase authentication, database row-level controls, service-role-only administrative functions, signed Stripe webhook verification, time-limited one-time checks, single-use merchant-scoped reward scan tokens, rate limits, security headers, and audit records for privileged actions.
External services
The current application can send relevant data to Supabase and PostgreSQL for data and authentication, Stripe for subscriptions and billing, Twilio Verify for phone codes, Resend for email, browser Web Push services for push delivery, Vercel for deployment and scheduled jobs, Google Places for optional venue suggestions, OpenStreetMap Nominatim for venue-address geocoding, PostHog for optional pseudonymous server-side analytics, and Sentry for optional technical error reporting.
Marketing and analytics controls
Customer marketing choices are stored separately from loyalty participation. First-party product events are stored in Supabase. Optional PostHog processing uses server-generated pseudonyms and an allowlist of properties; contact details, IP addresses, URLs, precise coordinates, provider identifiers, tokens, and secrets are rejected from the external analytics payload. Optional Sentry is configured with default personal-information collection disabled.
Privacy requests and exports
Privacy, access, export, deletion, and consent requests are executed through audited administrative workflows. Current customer exports include profile information, memberships, stamps, rewards, consent records, notifications, and first-party product events. A deletion request revokes sessions, disables push subscriptions, cancels queued notifications, scrubs linked pending invitations, and anonymises direct customer identifiers where the ledger must remain.
Retention and deletion
Abandoned verified customer identities without protected activity are eligible for anonymisation after seven days. Other stale customer identifiers are eligible for anonymisation after 365 days without recent customer, membership, stamp, or reward activity. Pending reward invitations expire after 90 days, matching details are scrubbed, and terminal invitation rows are eligible for deletion after 365 days. Bulk loyalty invitation recipient contact is stored encrypted and scrubbed at a terminal state or 30-day link expiry, abandoned drafts are purged after 24 hours, and contact-free terminal rows are deleted after 365 days, while unsubscribe suppression hashes are retained. Loyalty, consent, fraud, billing, product-event, and audit records may remain in anonymised form because the current application does not encode a general deletion period for those ledgers.
End of merchant service
When a merchant subscription is cancelled, Stripe and Nabaperks retain the recorded subscription state and cancellation timing. Loyalty operations are paused when billing is no longer active or trialling. Cancellation does not automatically delete customer loyalty, reward, consent, billing, product-event, fraud, or audit records, and privacy requests continue through the audited request workflow.