What security standards does Referral Factory follow?
Referral Factory is SOC 2 Type II audited, ISO 27001 certified and GDPR compliant. Request the current reports, certificates and scope when your security or procurement team needs evidence.
Half price through October on Basic and Pro plans. New customers only. See pricing
Learn about Referral Factory security, privacy and compliance, and protect your account and referral programs from fraud and abuse.
Use these guides to understand how Referral Factory protects customer data, secure access to your account, and reduce fraud, bot sign-ups and self-referrals in your campaigns.
Send this topic context to support and we will help you find the next step.
Understand Referral Factory’s security standards, data protection, account access controls, campaign safeguards and hosting options.
Protect your account with two-factor authentication, individual teammate access, appropriate permissions, SSO and secure credentials.
Understand Referral Factory’s GDPR position, controller and processor responsibilities, campaign checks and available privacy documentation.
Learn what Referral Factory’s SOC 2 Type II report covers at a high level and how to request the current report for review.
Understand Referral Factory’s ISO 27001 certification status and how to request the current certificate, scope and dates.
Use a practical checklist for referral-program privacy, marketing, rewards, data retention, campaign terms and jurisdiction-specific review.
Reduce referral abuse with reCAPTCHA, email verification, qualification rules, reward review, referral limits and activity checks.
Reduce self-referrals with unique email checks, verification, qualification rules, reward review, referral limits and clear campaign terms.
Enable reCAPTCHA in Referral Factory campaign settings to reduce automated form submissions, then test the public referral journey.
Reduce automated sign-ups with reCAPTCHA, email verification, qualification rules, reward review and suspicious-activity checks.
Understand how same-email self-referrals are blocked and what to review when someone uses a different email address.
Referral Factory is SOC 2 Type II audited, ISO 27001 certified and GDPR compliant. Request the current reports, certificates and scope when your security or procurement team needs evidence.
Use two-factor authentication, give each teammate a separate login, limit permissions, remove old access and protect API and integration credentials. SAML SSO is available on supported plans.
Use reCAPTCHA, email verification, qualification rules, referral limits and reward review. Check unusual activity in the Leads view before issuing high-value rewards.
No. Referral Factory provides platform controls and documentation, but your organisation remains responsible for the notices, permissions, campaign terms, retention rules and local requirements that apply to its program.
If a referred Lead qualifies through Stripe and that payment is later refunded, Referral Factory can reverse the qualification and return the Lead from Qualified to Pending.
Use Webhooks when an issued Referral Factory reward should be sent to an endpoint that your business controls. This is useful for adding loyalty points, triggering an internal payout, adding account credit, updating a customer wallet or passing reward information to your own rewards platform.
Send automated campaign emails and one-time Email blasts to referrers and leads directly from Referral Factory.
Manage your plan, billing cycle, payment method, billing email and invoice history from your Referral Factory account.