01
Information stored
The rewards ledger stores a pseudonymous participant ID, a one-way hash of the private access code, consent version and time, account-access timestamps, reward-event metadata, masked evidence references, approval status, and operator audit records.
02
Information not stored
The rewards ledger does not store participant names, email addresses, phone numbers, delivery addresses, wallet addresses, seed phrases, private keys, payment cards, bank details, or blockchain transactions.
03
Why the information is used
The limited information is used to authenticate participant access, verify eligible activity, calculate approved and pending points, show reward history, prevent duplicate credit and abuse, resolve questions, and maintain an operational audit trail.
04
Separation from delivery records
S2DP delivery operations may maintain order information in their own systems. The rewards ledger uses a non-personal evidence reference and does not expose or duplicate delivery addresses or payment information.
05
Session storage
After successful access, the site places a temporary random session token in the participant’s browser session storage. The server stores only a hash of that token. The session expires after 30 minutes and is removed from the browser when the tab session ends or the participant signs out.
06
Sharing
Rewards data is available only to the participant and authorized DaPoint operators who need it for verification, support, security, or program administration. It is not sold for advertising or used for individualized pricing.
07
Retention
Pilot records are kept only as long as reasonably needed for the active pilot, disputes, fraud prevention, audit, accounting, and legal obligations. A final retention schedule must be approved before broader activation.
08
Security
Access credentials and session tokens are stored as one-way hashes. Administrative access is separately authenticated, database queries are bound, responses are not cached, and the public participant view masks internal evidence references.
09
Participant choices
Participation is optional. A participant may request correction, access review, or account closure through DaPoint support using the participant ID. Because the rewards ledger does not store contact information, a lost access code cannot be recovered without a separately verified support process.
10
Incident response
DaPoint will investigate suspected unauthorized access and follow applicable Louisiana notice duties if protected personal information is affected. The narrow data design reduces—but does not eliminate—security risk.
11
Professional review
This notice is a prelaunch operating draft and not attorney-approved legal advice. The correct operating entity, final retention period, support procedure, and all production disclosures require confirmation before broader public use.