How we protect your data and your customers' data.
All data transmitted between your browser and our servers is encrypted using TLS (HTTPS). Data at rest is encrypted using AES-256. Your session tokens are stored securely and rotated regularly.
We use phone-based verification to authenticate your identity. There are no passwords to forget, leak, or guess. Every login requires a fresh verification code sent to your phone.
Sessions are protected by CSRF tokens on every state-changing request, and session cookies are HTTP-only to prevent script access.
All payment processing is handled by Stripe, a PCI Level 1 certified payment processor. Your card details are entered directly into Stripe's secure forms — they never touch our servers.
Our application runs on modern cloud infrastructure with automated backups, monitoring, and failover. We use industry-standard practices for server hardening, dependency management, and incident response.
If you discover a security vulnerability, please report it to security@startmyown.restaurant. We take all reports seriously and will respond promptly. Please do not publicly disclose vulnerabilities before we've had a chance to address them.
For any security-related questions, contact us at security@startmyown.restaurant.