User data flows
This page describes how personal data moves through Masivo for privacy and compliance review: what categories are processed, where they are stored, how long they are kept, when they are shared, and what happens on deletion. Masivo acts as a processor. Your organization decides what to collect from end users and which integrations and campaigns to enable.Each Masivo account is an isolated workspace. Data from one account is not accessible to other Masivo customers.
Overview
From signup to loyalty, marketing, and third-party tools
Field-level inventories are in each flow section below.
Where data is stored
Exported reports and import files may use the same US regions or regions you choose (for example Amazon S3).
How long we keep data
Retention depends on data type and whether the user is still active. Third-party tools apply their own retention after sync.
Custom behavioral event types follow the Smart Archiver pipeline: after 30 days in the primary database, rows move to Parquet files in object storage and are removed from live queries. Audience rehydration can temporarily restore archived rows.
| Wallet transactions | 1 year → backup | Retained | Up to 10 years |
| Journey progress | 7 days → backup | Retained | Up to 10 years |
| Push device identifiers | Until configured expiry (default 270 days; 60 days is the recommended option) | — | — |
| CSV export downloads | — | 30 days after generation | — |
Reporting-only retention (Oregon): events/customers/transactions/tracking up to 10 years; rolling spend summaries 2 years; audience change snapshots 2 years; temporary audience comparisons 1 month; API logs 365 days; audit logs 30 days.
The analytics system stores an enriched transaction record that denormalizes the customer’s name, email, date of birth, and gender alongside each transaction for the duration of the analytics retention period (up to 10 years). This is not an anonymized aggregate — it links identifiable personal data to purchase history in the reporting layer.
Data deletion
Masivo removes data at two levels: customer (full loyalty/marketing profile) and contact (single CDP touchpoint). Deleting a customer does not delete linked contacts. Deletion is initiated by your organization (dashboard or your integration). It always starts with deactivation, then permanent removal after a waiting period.From deletion request to permanent removal
Customer deletion
Immediately: profile, wallet, activity, and transactions are deactivated; audience and journey membership is removed; marketing stops; connected tools receive a deletion signal (async).
~30 days later: permanent deletion from the primary database and reporting customer records. May be delayed if unreconciled transactions exist. Deactivated activity rows may persist until separate archival runs.
Contact deletion: the CDP touchpoint is marked as deleted and excluded from new audience evaluations. The customer profile linked to it is not affected. No deletion signal is sent to third parties. There is no scheduled permanent purge for contacts at this time — the record remains in the primary database indefinitely after soft deletion unless removed through a manual operation.
May persist after deletion: backup archives, reporting activity rows (until TTL), enriched analytics records, aggregated dashboard totals, and third-party copies under partner policies. See retention table above.
Masivo does not send a dedicated deletion notification to your organization’s backend. Consent withdrawal stops future processing without deleting the profile.
Privacy & consent
Your organization records consent on each customer profile. Masivo checks purposes before loyalty processing, messaging, or third-party sync.Consent controls use; deletion stops future processing
Also stored when provided: consent timestamp, policy version, and IAB TCF consent string.
Consent data stored
Default behavior when no consent record exists
When a consent record is present, each purpose must be explicitly allowed (true) — the absence of a key is treated as permitted, but an explicit false blocks that purpose.
Effect of consent changes
Registration flow
When someone signs up through your integrated channels, Masivo saves their profile, creates a loyalty wallet, and starts configured loyalty and marketing flows.New user registration
Data collected at registration
Typical fields: name, email, phone, and any additional attributes your organization chooses to collect. A loyalty wallet is created automatically.Customer profile data
Contact touchpoint data (CDP)
Not collected by default
Unless your organization sends them: precise GPS, biometrics, GDPR special-category data, or full payment card numbers. Sensitive data in custom fields remains your organization’s responsibility for lawful basis and minimization. Identified customers can enter audiences shortly after registration. Anonymous users use placeholder identity values: loyalty may apply, but audience-based marketing and segment-dependent messages do not until they identify themselves and the profile is merged.Activity & events
Activity follows one of two paths depending on configuration and consent.Loyalty activity vs. analytics-only activity
Blocked when
behavioral_campaigns consent is denied (activity may still be stored). Anonymous users: loyalty may apply; audience marketing does not until identification.
Activity data
Analytics-only activity (page views, app opens) uses the same storage model but, by default, does not change wallet balances.
Loyalty data
Derived data
Masivo creates these from profile and activity inputs:Support messages
If your organization uses Masivo’s support messaging feature, the following data is stored per conversation thread:
Message content may contain any personal information the customer or support agent chooses to include. Masivo does not inspect or restrict this content.
Reviews and survey responses
If your organization uses Masivo’s review or feedback forms:
Free-text comments may contain personal information about the respondent or third parties.
Marketing & destinations
Profiles and activity power segmentation, automated marketing, and third-party audience sync.From profile to message or ad platform
Audiences
Membership updates when rules change, qualifying activity arrives (identified users), lists are imported, or scheduled jobs remove non-matching members.Marketing data
Marketing measurement
When your organization uses tracked links or attribution:Automations, push, and third parties
Automations trigger from activity or audience membership. Push devices: requires a registered device identifier (token, device type, OS version, expiration) and push consent — see Customer profile data. Push tokens are also sent to Google Firebase (FCM) to deliver the notification. Connected integrations can sync audiences (full or incremental) and activity to ad platforms, CRM tools, and data warehouses. All sharing is gated by vendor consent — see Privacy & consent.Third-party data transfers
The table below describes exactly what personal data leaves Masivo to each integration, and in what form. All transfers are conditional on vendor consent and integration settings configured by your organization.Meta encoding clarification: Masivo uses two different Meta audience integrations. In the v1 integration, email and phone are Base64-encoded (a reversible encoding, not a cryptographic hash), and demographic fields (first name, last name, date of birth, gender, city, state, country, zip) are transmitted in plain text. In the v2 integration and in the direct add/remove path, only email is SHA-256 hashed. For Meta Pixel and App Events, email and phone are also Base64-encoded. Base64 does not provide the same privacy protection as SHA-256 and is decodable without a key.