Readable, operator-friendly policy language for the MVP.
Profile, organization, campaign, evidence metadata, payout method tokens, notifications, and audit records. Sensitive provider secrets remain outside the UI and are never shown back to operators.
Data is used to enforce eligibility, review proof, calculate wallet balances, pay ambassadors, and investigate exceptions. The public site stays informational and does not expose private evidence paths.
Primary records live in PostgreSQL, transient work queues in Redis, and private evidence in local or R2-compatible storage. Access depends on authenticated role and tenant membership.
Need the full legal packet?
The docs set can expand this summary into a jurisdiction-specific legal artifact without changing the public route structure.