Encryption

All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). Data at rest is encrypted using AES-256. Your session tokens are stored securely and rotated regularly.

Authentication

We use phone-based verification to authenticate your identity. There are no passwords to forget, leak, or guess. Every login requires a fresh verification code sent to your phone.

Sessions are protected by CSRF tokens on every state-changing request, and session cookies are HTTP-only to prevent script access.

Secure payments

All payment processing is handled by Stripe, a PCI Level 1 certified payment processor. Your card details are entered directly into Stripe's secure forms — they never touch our servers.

Data handling

  • Minimal collection — We only collect the information we need to run your account and deliver orders.
  • No selling — We never sell or share your data with advertisers or data brokers.
  • Access controls — Internal access to customer data is restricted to essential personnel and logged.
  • Regular audits — We review our security practices regularly and update them as threats evolve.

Infrastructure

Our application runs on modern cloud infrastructure with automated backups, monitoring, and failover. We use industry-standard practices for server hardening, dependency management, and incident response.

Responsible disclosure

If you discover a security vulnerability, please report it to security@startmyown.restaurant. We take all reports seriously and will respond promptly. Please do not publicly disclose vulnerabilities before we've had a chance to address them.

Questions

For any security-related questions, contact us at security@startmyown.restaurant.