← All posts

Sensitive information stays private

Some of what you collect from crew and staff is more private than a shirt size. A tax file number, bank details, a passport scan, a police check. Until now those sat in 1pm like every other answer: visible to anyone on your team who opened the event.

Now you can mark them Sensitive, and 1pm treats them differently from everything else.

What changes

Tick Sensitive on a Text, Date or Upload request, or on a custom contact field. From then on:

  • The answer is masked everywhere. On the event, the Requests page, the contact and in reports it reads as dots with the last three characters, like ••••• 782.
  • Only admins see it in full. An admin clicks View beside the masked value. The Team page now sets each person as an Admin or a Member, and Members see the dots.
  • Every view is logged. Who looked, when, at whose answer, from which IP address. The new Sensitive information access report lists it all, with a CSV.
  • It is stored encrypted, with the key kept outside the database, so a copy of the database only ever holds scrambled text.
  • It stays out of emails and exports. The “requests complete” email says an answer was given without printing it, and the account export writes (sensitive) unless you tick to include it.

Everything else works as before. A sensitive request can still be required, chased, reviewed and carried in a request pack. The starter packs already mark the obvious ones: tax forms, bank account numbers, super member numbers, right to work, police and DBS checks.

Deleting it on a schedule

Sensitive information is kept until you delete it, because employers usually have to hold payroll records for years. If you would rather it went sooner, Account > Profile has a Sensitive information card: delete it 30 days, 90 days, 1 year, 5 years or 7 years after a portal closes or after the event date.

You get an email 7 days before anything goes. The answers are removed and the record stays, so a request still reads as complete, with “Removed on” and the date where the answer was.

Keeping sensitive information private has the details.