Security

Last updated 4 October 2026

Kinetiq is run by the organization operating this service and is designed to support your GDPR, CCPA and SOC 2 obligations. This page lists the controls built into the service today. Each one names where you can see it in the product.

Hosting and transport

Access control

Single sign-on

Audit trail

Data protection

Privacy operations

Integrations

Application security

Reporting a vulnerability

There is no public intake address yet. Customers report through their account representative. To report a suspected vulnerability, give the steps to reproduce it and the address of the affected page or endpoint. Test only against your own organization's data, do not access or change anyone else's, and do not run denial-of-service tests. This page is the contact named in the site's /.well-known/security.txt.

Personal data we hold

Generated from the same data map the console shows.

Personal data by category
CategoryWhat it coversProtection
Fan contact detailsThe email address, and the name and postal code when an activation asks for them, given by a fan who signs up at a scan.Encrypted, Keyed hash, Plain
Consent and privacy choicesThe consent wording a fan agreed to with its policy version, age confirmation, opt-out of sale or sharing, and the preference link.Plain, Derived
Scan, offer and outcome activityWhen and where a fan scanned, offers issued and redeemed, and outcomes such as purchases linked to the fan.Plain, Derived
Device and network identifiersIP addresses and a random device identifier, used to ignore repeat scans, flag bursts and record sign-ins.Plain
Console member accountsMembers' sign-in email, password hash, single sign-on subject and sign-in times.Plain, Derived
Messages to connected systemsEvent messages queued and delivered to the organization's own systems by signed webhook, and stored ingest responses.Plain
Privacy requestsRecords of access, rectification and erasure requests, kept as evidence that each was handled.Encrypted, Keyed hash, Plain
Assistant conversationsThe questions members ask the assistant, its answers and their feedback on them, kept 90 days. Conversations are included in the organization export.Encrypted
Audit trailThe hash-chained record of who did what in the console, with the IP address of sign-ins and other actions.Plain