How we protect business and member data
Members Request Desk is operated by NEMO Australia Pty Ltd(ABN 60 631 429 055). We automate membership suspension requests for businesses using Mindbody and collect only the information needed to provide the service. This page explains the controls currently in place.
Last updated 30 July 2026
Where your data goes
A member submits a request; we verify it, apply your rules, and submit eligible suspensions to Mindbody. Supporting providers (below) handle limited data such as SMS verification and email. Our primary database is hosted in Sydney; some providers process limited data overseas.
Data protection
✓ Credentials are encrypted
Each business's Mindbody credentials are AES-256-GCM encrypted before they touch the database. No API key, username or password is ever stored in plaintext.
✓ Each business's data is separated
Records are separated per business and access is limited to authorised services and staff. Technically, every table uses Postgres row-level security (RLS), and the most sensitive tables are restricted to server-side access only.
✓ Encrypted in transit
All traffic — browser, our servers, and the Mindbody API — is served over TLS/HTTPS.
✓ Credentials and secrets are protected
Secrets are never committed to source control or written to logs; access is limited to server-side code on a need-to-know basis.
Data residency & retention
✓ Primary database in Sydney
Our primary database is hosted in the Supabase Sydney region. Some providers may process limited data overseas; their purposes and locations are listed below and in the Privacy Policy.
✓ Medical category, not medical details
We may record that a request uses the medical category, but we do not ask for or store diagnoses, certificates or other health details. Any medical evidence is handled directly by the business, off our platform.
✓ Retention timeframes
Verification codes are single-use, expire within minutes, and are purged within 30 days. Personal data on closed requests is de-identified after 24 months by an automated job. When an account is closed, we delete or de-identify personal data within 30 days. Billing records are kept for 5 years as required by Australian tax law. Deleted data ages out of encrypted backups on our provider's standard rotation.
✓ Access & deletion requests (DSAR)
A DSAR is simply a request to access or delete personal data. Businesses can request an export or deletion of their data, and we help them answer their members' requests, subject to the retention timeframes above.
Safe, controlled automation
✓ Verified identity
Every request is confirmed with a one-time code sent to the member's contact on file in Mindbody — not what was typed into the form — which helps reduce unauthorised requests.
✓ Your business stays in control
Your own rules run on every request; anything unusual (balance owed, medical category, identity mismatch) is routed to staff review instead of auto-processing. A master kill-switch can pause all automation instantly.
✓ Duplicate & retry checks
Duplicate and retry checks reduce the risk of repeated actions, and results are reconciled against Mindbody. If a mismatch is detected, the request is held for staff review rather than retried blindly.
✓ Audit trail
Every action is logged with correlation IDs, so any outcome can be traced end to end.
Operating controls
We use a managed, encrypted database with provider-managed backups, least-privilege access to production, and logged, reconciled automation (above). We hold no third-party security certifications (SOC 2, ISO 27001, PCI) and don't display badges we haven't earned. We publish updates here as controls change.
Operating-controls summary last updated 30 July 2026.
Compliance
We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and — where it applies — the GDPR. For member suspension data the business is the data controller and we act as its processor.
Subprocessors
We use a small set of trusted providers and do not sell personal information. We'll notify customers of material changes to this list. Last updated 30 July 2026.
| Provider | Purpose | Data involved | Processing / storage |
|---|---|---|---|
| Supabase | Database & auth | All service data | Sydney, AU |
| Vercel | Hosting & compute | Requests in transit | Global edge; US region |
| Twilio | SMS verification | Member phone number | United States |
| Resend | Transactional email | Member/staff email | United States |
| Stripe | Business billing | Account & billing details | United States / global |
| Mindbody | The business's own platform we integrate with | Member & contract data | United States |
Processing locations are indicative and may change; see the Privacy Policy for the authoritative cross-border detail.
Privacy questions
Data access, deletion or general privacy queries: privacy@membersrequestdesk.com.
Report a vulnerability
Please disclose responsibly to security@membersrequestdesk.com (see /.well-known/security.txt). We aim to acknowledge critical reports within 2 business days and others within 5.