Skip to main content

User data flows

This page describes how personal data moves through Masivo for privacy and compliance review: what categories are processed, where they are stored, how long they are kept, when they are shared, and what happens on deletion. Masivo acts as a processor. Your organization decides what to collect from end users and which integrations and campaigns to enable.
Each Masivo account is an isolated workspace. Data from one account is not accessible to other Masivo customers.

Overview

From signup to loyalty, marketing, and third-party tools

Personal data enters through registration, activity feeds, CDP contacts, consent updates, imports, or connected sources. Masivo uses it to run loyalty programs, segment audiences, deliver marketing, produce reports, and — when you configure integrations — sync to third parties. Field-level inventories are in each flow section below.

Where data is stored

Exported reports and import files may use the same US regions or regions you choose (for example Amazon S3).

How long we keep data

Retention depends on data type and whether the user is still active. Third-party tools apply their own retention after sync. Custom behavioral event types follow the Smart Archiver pipeline: after 30 days in the primary database, rows move to Parquet files in object storage and are removed from live queries. Audience rehydration can temporarily restore archived rows. | Wallet transactions | 1 year → backup | Retained | Up to 10 years | | Journey progress | 7 days → backup | Retained | Up to 10 years | | Push device identifiers | Until configured expiry (default 270 days; 60 days is the recommended option) | — | — | | CSV export downloads | — | 30 days after generation | — | Reporting-only retention (Oregon): events/customers/transactions/tracking up to 10 years; rolling spend summaries 2 years; audience change snapshots 2 years; temporary audience comparisons 1 month; API logs 365 days; audit logs 30 days.
The analytics system stores an enriched transaction record that denormalizes the customer’s name, email, date of birth, and gender alongside each transaction for the duration of the analytics retention period (up to 10 years). This is not an anonymized aggregate — it links identifiable personal data to purchase history in the reporting layer.
Active profiles have no automatic expiry. Backup copies support auditing and audience recalculation, not live customer operations. Aggregated report totals may outlive an individual profile — relevant for deletion requests.

Data deletion

Masivo removes data at two levels: customer (full loyalty/marketing profile) and contact (single CDP touchpoint). Deleting a customer does not delete linked contacts. Deletion is initiated by your organization (dashboard or your integration). It always starts with deactivation, then permanent removal after a waiting period.

From deletion request to permanent removal

Customer deletion

Immediately: profile, wallet, activity, and transactions are deactivated; audience and journey membership is removed; marketing stops; connected tools receive a deletion signal (async). ~30 days later: permanent deletion from the primary database and reporting customer records. May be delayed if unreconciled transactions exist. Deactivated activity rows may persist until separate archival runs. Contact deletion: the CDP touchpoint is marked as deleted and excluded from new audience evaluations. The customer profile linked to it is not affected. No deletion signal is sent to third parties. There is no scheduled permanent purge for contacts at this time — the record remains in the primary database indefinitely after soft deletion unless removed through a manual operation.
If an end user exercises their right to erasure and they have CDP contact records (not just a customer profile), those contacts require a separate deletion request and do not follow the automated ~30-day purge cycle. Your organization should account for this when handling data subject requests.
May persist after deletion: backup archives, reporting activity rows (until TTL), enriched analytics records, aggregated dashboard totals, and third-party copies under partner policies. See retention table above. Masivo does not send a dedicated deletion notification to your organization’s backend. Consent withdrawal stops future processing without deleting the profile. Your organization records consent on each customer profile. Masivo checks purposes before loyalty processing, messaging, or third-party sync.

Consent controls use; deletion stops future processing

Also stored when provided: consent timestamp, policy version, and IAB TCF consent string.
If a customer profile has no consent record, Masivo treats all purposes as permitted by default. Your organization is solely responsible for collecting valid consent from end users before creating profiles in Masivo. Masivo does not verify that consent was obtained.
When a consent record is present, each purpose must be explicitly allowed (true) — the absence of a key is treated as permitted, but an explicit false blocks that purpose.

Registration flow

When someone signs up through your integrated channels, Masivo saves their profile, creates a loyalty wallet, and starts configured loyalty and marketing flows.

New user registration

Custom and free-form data: Customer profiles, contacts, and activity events each contain open JSON fields (metadata, tags, data, traits) that your organization can populate with any content. Masivo does not validate or restrict what goes into these fields. Any personal data your organization stores in these containers is subject to the same retention and deletion schedules as structured fields — but your organization bears sole responsibility for ensuring that data stored here has a valid legal basis, is proportionate, and is disclosed to end users in your privacy notice.

Data collected at registration

Typical fields: name, email, phone, and any additional attributes your organization chooses to collect. A loyalty wallet is created automatically.

Customer profile data

Contact touchpoint data (CDP)

Not collected by default

Unless your organization sends them: precise GPS, biometrics, GDPR special-category data, or full payment card numbers. Sensitive data in custom fields remains your organization’s responsibility for lawful basis and minimization. Identified customers can enter audiences shortly after registration. Anonymous users use placeholder identity values: loyalty may apply, but audience-based marketing and segment-dependent messages do not until they identify themselves and the profile is merged.

Activity & events

Activity follows one of two paths depending on configuration and consent.

Loyalty activity vs. analytics-only activity

Blocked when behavioral_campaigns consent is denied (activity may still be stored). Anonymous users: loyalty may apply; audience marketing does not until identification.

Activity data

Analytics-only activity (page views, app opens) uses the same storage model but, by default, does not change wallet balances.

Loyalty data

Derived data

Masivo creates these from profile and activity inputs:

Support messages

If your organization uses Masivo’s support messaging feature, the following data is stored per conversation thread: Message content may contain any personal information the customer or support agent chooses to include. Masivo does not inspect or restrict this content.

Reviews and survey responses

If your organization uses Masivo’s review or feedback forms: Free-text comments may contain personal information about the respondent or third parties.

Marketing & destinations

Profiles and activity power segmentation, automated marketing, and third-party audience sync.

From profile to message or ad platform

Audiences

Membership updates when rules change, qualifying activity arrives (identified users), lists are imported, or scheduled jobs remove non-matching members.

Marketing data

Marketing measurement

When your organization uses tracked links or attribution:

Automations, push, and third parties

Automations trigger from activity or audience membership. Push devices: requires a registered device identifier (token, device type, OS version, expiration) and push consent — see Customer profile data. Push tokens are also sent to Google Firebase (FCM) to deliver the notification. Connected integrations can sync audiences (full or incremental) and activity to ad platforms, CRM tools, and data warehouses. All sharing is gated by vendor consent — see Privacy & consent.

Third-party data transfers

The table below describes exactly what personal data leaves Masivo to each integration, and in what form. All transfers are conditional on vendor consent and integration settings configured by your organization.
Meta encoding clarification: Masivo uses two different Meta audience integrations. In the v1 integration, email and phone are Base64-encoded (a reversible encoding, not a cryptographic hash), and demographic fields (first name, last name, date of birth, gender, city, state, country, zip) are transmitted in plain text. In the v2 integration and in the direct add/remove path, only email is SHA-256 hashed. For Meta Pixel and App Events, email and phone are also Base64-encoded. Base64 does not provide the same privacy protection as SHA-256 and is decodable without a key.
Data already sent to a third party is not recalled when consent is withdrawn or a customer is deleted. Each destination applies its own retention and deletion policies. Your organization is responsible for managing deletion requests with each connected platform.