membersreqestdesk
Trust Centre

How we protect business and member data

Members Request Desk is operated by NEMO Australia Pty Ltd(ABN 60 631 429 055). We automate membership suspension requests for businesses using Mindbody and collect only the information needed to provide the service. This page explains the controls currently in place.

Last updated 30 July 2026

Where your data goes

Member formMembers Request DeskMindbody

A member submits a request; we verify it, apply your rules, and submit eligible suspensions to Mindbody. Supporting providers (below) handle limited data such as SMS verification and email. Our primary database is hosted in Sydney; some providers process limited data overseas.

Data protection

Credentials are encrypted

Each business's Mindbody credentials are AES-256-GCM encrypted before they touch the database. No API key, username or password is ever stored in plaintext.

Each business's data is separated

Records are separated per business and access is limited to authorised services and staff. Technically, every table uses Postgres row-level security (RLS), and the most sensitive tables are restricted to server-side access only.

Encrypted in transit

All traffic — browser, our servers, and the Mindbody API — is served over TLS/HTTPS.

Credentials and secrets are protected

Secrets are never committed to source control or written to logs; access is limited to server-side code on a need-to-know basis.

Data residency & retention

Primary database in Sydney

Our primary database is hosted in the Supabase Sydney region. Some providers may process limited data overseas; their purposes and locations are listed below and in the Privacy Policy.

Medical category, not medical details

We may record that a request uses the medical category, but we do not ask for or store diagnoses, certificates or other health details. Any medical evidence is handled directly by the business, off our platform.

Retention timeframes

Verification codes are single-use, expire within minutes, and are purged within 30 days. Personal data on closed requests is de-identified after 24 months by an automated job. When an account is closed, we delete or de-identify personal data within 30 days. Billing records are kept for 5 years as required by Australian tax law. Deleted data ages out of encrypted backups on our provider's standard rotation.

Access & deletion requests (DSAR)

A DSAR is simply a request to access or delete personal data. Businesses can request an export or deletion of their data, and we help them answer their members' requests, subject to the retention timeframes above.

Safe, controlled automation

Verified identity

Every request is confirmed with a one-time code sent to the member's contact on file in Mindbody — not what was typed into the form — which helps reduce unauthorised requests.

Your business stays in control

Your own rules run on every request; anything unusual (balance owed, medical category, identity mismatch) is routed to staff review instead of auto-processing. A master kill-switch can pause all automation instantly.

Duplicate & retry checks

Duplicate and retry checks reduce the risk of repeated actions, and results are reconciled against Mindbody. If a mismatch is detected, the request is held for staff review rather than retried blindly.

Audit trail

Every action is logged with correlation IDs, so any outcome can be traced end to end.

Operating controls

We use a managed, encrypted database with provider-managed backups, least-privilege access to production, and logged, reconciled automation (above). We hold no third-party security certifications (SOC 2, ISO 27001, PCI) and don't display badges we haven't earned. We publish updates here as controls change.

Operating-controls summary last updated 30 July 2026.

Compliance

We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and — where it applies — the GDPR. For member suspension data the business is the data controller and we act as its processor.

Subprocessors

We use a small set of trusted providers and do not sell personal information. We'll notify customers of material changes to this list. Last updated 30 July 2026.

ProviderPurposeData involvedProcessing / storage
SupabaseDatabase & authAll service dataSydney, AU
VercelHosting & computeRequests in transitGlobal edge; US region
TwilioSMS verificationMember phone numberUnited States
ResendTransactional emailMember/staff emailUnited States
StripeBusiness billingAccount & billing detailsUnited States / global
MindbodyThe business's own platform we integrate withMember & contract dataUnited States

Processing locations are indicative and may change; see the Privacy Policy for the authoritative cross-border detail.

Privacy questions

Data access, deletion or general privacy queries: privacy@membersrequestdesk.com.

Report a vulnerability

Please disclose responsibly to security@membersrequestdesk.com (see /.well-known/security.txt). We aim to acknowledge critical reports within 2 business days and others within 5.