Never send a card number. Send payment.bin (up to 8 digits) and payment.last4 only. A full card number in the payload, including payment.card_token, is rejected with 400 CARD_NUMBER_DETECTED. The scan skips a scalar transaction_id and a valid international user.phone.
Prefer raw user.email and user.phone. The server hashes them with a platform secret before they are used for linking. If you cannot send raw values, email_hash and phone_hash link only events carrying the same value, and a digest you compute yourself will not join the identity built from a raw address. When both are sent, the raw value wins; if a raw phone yields no hash, your phone_hash is used.
Raw identity data is never compared across tenants; cross-tenant reputation uses aggregated confirmations only.
Link signals are returned masked (for example j***@example.com), never raw.
A string containing the NUL character (U+0000) is rejected with 400.
To erase a person, call DELETE /v1/accounts/{id} with a live key.