SilentChat

Recommendation Program — Audit & Compliance

Last updated: September 19, 2026

Logged Events

Each lifecycle step writes an audit log entry to the audit_log table (resource_type=referral, resource_id=<referral_id>). Visible at /admin/audit-log (filter "Resource = referral") and on the referral detail page as a chronological timeline.

ActionTriggerPayload
referral.createdCode wallet created for the first timecode, tenant_id
referral.redeemedCode used at signupcode, referrer_tenant_id, referred_tenant_id
referral.qualifiedQualifying trigger mettrigger, qualified_at
referral.rewardedStripe grant successfulreward_type, value, currency, stripe_credit_id / stripe_coupon_id
referral.grant_failedStripe call failedreason
referral.expiredQualification window expiredreason, expiration_days
referral.voidedClawback or manual cancellationreason, admin_override
referral.admin_overrideManual action on detail pageaction (force_qualify / manual_grant / void), note
referral.config_updatedConfiguration changedbefore, after
referral.program_toggledMaster switch toggledbefore, after

Retention

Audit log entries are deleted after 12 months (up to 24 months with a longer plan viewing period). Referral records exist as long as the associated tenants — if a tenant is deleted under GDPR, its referrals are anonymized (referrer_tenant_id / referred_tenant_id remain for statistical evaluation, but no link to deleted tenant master data).

GDPR

  • Referral tables contain no PII at the column level — tenant_id references + Stripe IDs are the only personal references, and both are pseudonymized identifiers.
  • On tenant hard delete (/admin/tenants/:id → GDPR deletion) foreign keys are set to NULL; statistical referral history information is preserved.
  • Email sending (referral_*-templates) logs only the recipient email in email_logs — even that is subject to the email log retention (default 90 days).

Terms & Conditions Template

Activation of the program requires a Terms & Conditions URL (required field in the configuration). You can find a template in marketing/.../legal/referral-terms — adapt and publish before you activate the program. Minimum content:

  1. Participation conditions — who can refer, which plans are excluded.
  2. Reward calculation — value, payout method (Stripe credit, no cash), taxes.
  3. Qualifying conditions — when a referral is considered qualified.
  4. Clawback — under what circumstances the reward is revoked.
  5. Anti-abuse — self-referral prohibited, limits, right to manual override.
  6. Right to terminate the program — we can end the program at any time; already qualified referrals will still be paid out.

Referrer Information Obligation

If the program is actively promoted via email / social media, advertising labeling requirements may apply (UWG, influencer disclosure requirements). The terms and conditions template addresses this with an "advertising" disclaimer snippet.

Reports

  • /admin/referrals — live list + stats.
  • Audit log export — manual CSV export for accounting via /admin/audit-log (set filters → "Export").
  • Stripe dashboard — all reward bookings as balance_transactions with metadata.source=referral_program.