Recommendation Program — Audit & Compliance
Logged Events
Each lifecycle step writes an audit log entry to the
audit_log table (resource_type=referral, resource_id=<referral_id>).
Visible at /admin/audit-log (filter "Resource = referral") and
on the referral detail page as a chronological timeline.
| Action | Trigger | Payload |
|---|---|---|
referral.created | Code wallet created for the first time | code, tenant_id |
referral.redeemed | Code used at signup | code, referrer_tenant_id, referred_tenant_id |
referral.qualified | Qualifying trigger met | trigger, qualified_at |
referral.rewarded | Stripe grant successful | reward_type, value, currency, stripe_credit_id / stripe_coupon_id |
referral.grant_failed | Stripe call failed | reason |
referral.expired | Qualification window expired | reason, expiration_days |
referral.voided | Clawback or manual cancellation | reason, admin_override |
referral.admin_override | Manual action on detail page | action (force_qualify / manual_grant / void), note |
referral.config_updated | Configuration changed | before, after |
referral.program_toggled | Master switch toggled | before, after |
Retention
Audit log entries are deleted after 12 months (up to 24 months
with a longer plan viewing period). Referral records exist as long as
the associated tenants — if a tenant is deleted under GDPR,
its referrals are anonymized (referrer_tenant_id /
referred_tenant_id remain for statistical evaluation, but no
link to deleted tenant master data).
GDPR
- Referral tables contain no PII at the column level —
tenant_idreferences + Stripe IDs are the only personal references, and both are pseudonymized identifiers. - On tenant hard delete (
/admin/tenants/:id→ GDPR deletion) foreign keys are set to NULL; statistical referral history information is preserved. - Email sending (referral_*-templates) logs only the recipient
email in
email_logs— even that is subject to the email log retention (default 90 days).
Terms & Conditions Template
Activation of the program requires a Terms & Conditions URL (required field in
the configuration). You can find a template in
marketing/.../legal/referral-terms — adapt and publish
before you activate the program. Minimum content:
- Participation conditions — who can refer, which plans are excluded.
- Reward calculation — value, payout method (Stripe credit, no cash), taxes.
- Qualifying conditions — when a referral is considered qualified.
- Clawback — under what circumstances the reward is revoked.
- Anti-abuse — self-referral prohibited, limits, right to manual override.
- Right to terminate the program — we can end the program at any time; already qualified referrals will still be paid out.
Referrer Information Obligation
If the program is actively promoted via email / social media, advertising labeling requirements may apply (UWG, influencer disclosure requirements). The terms and conditions template addresses this with an "advertising" disclaimer snippet.
Reports
/admin/referrals— live list + stats.- Audit log export — manual CSV export for accounting via
/admin/audit-log(set filters → "Export"). - Stripe dashboard — all reward bookings as
balance_transactionswithmetadata.source=referral_program.