Security

Program data deserves clear boundaries.

Incenify protects program information with role-based access, private proof storage, and encryption. Review those safeguards alongside the data-handling choices for your program.

Access and protection

Safeguards for your program information.

Identity and permissions

Accounts have permissions for participant, partner, or administrative tasks. The platform checks the user’s organization, current role, and account status before granting access. Disabling an account or revoking its sessions blocks subsequent authenticated requests.

Within those controls, your program defines who qualifies to join and which permissions your staff need. Email verification, partner-domain rules, audience eligibility, and administrative approval support those decisions.

Program records and proof files

Access to program records is checked against the user’s organization. Sales-claim invoices and receipts are held in private storage. The application controls access to those files, using protected requests or links that expire.

Uploads are checked for permitted file type and size. Credentials used for privileged operations are kept out of participants’ browsers.

Encryption and infrastructure

Program data is encrypted in transit and at rest through the managed infrastructure supporting the service. Production access is restricted to authorized people and services with an operational or support responsibility.

Managed providers support hosting, sign-in, database, storage, and enabled communication or payment services. The DPA provides for a current list of providers that process customer data, available on written request.

Data handling

Data handling shaped around your program.

Purpose and collection

The configured workflow determines the information collected: account details, partner affiliation, eligibility, activity, rewards, and relevant communications. Delivery details or a mobile number may be needed for particular rewards or participation methods.

Incenify processes customer personal data to provide the agreed service and follow accepted, documented instructions. Proof requirements should identify the information needed for validation and exclude unrelated personal information.

AI and system connections

Incenify does not currently use AI to process receipts, proof documents, or claim validation. These workflows use configured rules and administrative review. Automated eligibility decisions are based on program rules.

Incenify can run independently of your internal systems or support agreed integrations. We define the data exchanged, purpose, access, and services involved as part of the program’s scope.

Retention, return, and deletion

A claim’s invoice, its validation outcome, and its transaction history may have different retention needs. We agree the periods and handling for each data category as part of your program.

The DPA sets out data return and deletion terms, including request timing, legal retention requirements, and treatment of backup copies.

Read retention and deletion terms

Ongoing operation

Records, recovery, and response.

Backups and recovery

Managed database backups support recovery of program records. Backup frequency and the available recovery window depend on the deployment’s configuration.

Uploaded files are stored separately. Database backups include references to those files, not their contents, so database restoration and file recovery are distinct.

Audit records and changes

Claim decisions and partner onboarding actions are recorded with the relevant program and the person or process responsible. Those records support investigation and operational review.

Security checks cover application behavior, access permissions, database access rules, and restricted pages and services. Relevant check results and their scope can be shared during review.

Incident communication

Under the DPA, we notify the customer without undue delay after becoming aware of a personal data breach. We provide available details about the affected information, likely consequences, and response, and cooperate as described in the agreement.

We use the customer’s designated contact. Report a suspected issue through your Incenify contact or our contact page so we can coordinate the next steps.

Customer diligence

A clear path through your security review.

We explain Incenify’s safeguards, supply the relevant documentation, and help your team work through additional requirements. Your questionnaire and review contacts help us coordinate the answers your organization needs.

We guide the discussion across hosting locations, subprocessors, access permissions, processing methods, retention, and recovery. Security-sensitive details are handled directly under the applicable confidentiality terms.

Documents for your review

Terms of service

Standard subscription terms, accepted with your proposal or order.

Data Processing Addendum

Processing instructions, subprocessors, incident notification, and data return or deletion.

Master Service Agreement

Service responsibilities, confidentiality, and security obligations when a separate MSA is agreed.

Privacy policy

How Incenify collects, uses, and shares information.

Your executed agreements govern the service and any program-specific commitments.