Our Commitment to Security
Security as a Foundation
Security is not an add-on at Klicktify — it is woven into our architecture, our development process, and our company culture. Loyalty platforms handle personal data that people trust us with: their name, phone number, email, purchase history, and personal preferences. We take that responsibility seriously. This page describes, in plain language, the measures we have in place to protect your data.
We do not make claims about security certifications we have not achieved. We state below what we have in place, and we are transparent about what we are working toward. If you have questions about our security practices, please contact security@klicktify.com.
Encryption
Data in Transit
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) 1.2 or higher. This protects your data from interception while it travels across the internet. You can verify this by checking that your browser shows a padlock icon when accessing https://klicktify.com.
Data at Rest
All data stored in our database (hosted on Neon / Lakebase Postgres) is encrypted at rest using industry-standard AES-256 encryption. This means that even if someone were to gain access to the physical storage or a backup, the data would be unreadable without the encryption keys.
Password Hashing
Account passwords are never stored in plaintext. They are hashed using bcrypt with a cost factor of at least 12, using a robust password hashing algorithm designed to resist brute-force attacks. Klicktify staff cannot see your plaintext password.
Authentication and Sessions
Two-Separate-Session Architecture
Klicktify operates two completely independent authentication systems:
- Merchant session (NextAuth): used by café owners and staff to access their dashboard, analytics, billing, and programme management. Authenticated via email and password.
- Member session (member-auth): used by Members to access their loyalty account, view points, and redeem rewards across any participating Merchant. This is a separate session infrastructure — a Member's session tokens cannot be used to access Merchant functionality and vice versa.
This separation means that a compromise of one system does not automatically compromise the other.
Session Security
Session tokens are cryptographically signed, HTTP-only, and scoped to the correct security origin. Session duration is limited: sessions expire after a period of inactivity or can be ended by the user signing out. A separate CSRF (Cross-Site Request Forgery) token protects all state-changing operations.
Tenant Isolation
Multi-Tenant Architecture
Klicktify is a multi-tenant platform: many Merchants share the same infrastructure, but each Merchant's data is logically isolated from the others. Specifically:
- Database access is controlled by row-level security policies and least-privilege role grants. A Merchant's database queries can only return data belonging to their own programme.
- Member data collected at one Merchant is never accessible to another Merchant without the Member's explicit action (e.g., joining the other Merchant's programme).
- A Member's global account identity is separate from any individual Merchant's membership data.
Access Controls
Principle of Least Privilege
Access to production systems, databases, and administrative functions is granted on a strict least-privilege basis. Only authorised personnel who require access for their role are granted it, and access is reviewed periodically.
Database Access
Database connections are protected by IP allow-listing. Direct database access is restricted to authorised engineering personnel via secure, audited channels. No database credentials are stored in source code or configuration files that could be exposed in version control.
Secure Software Development
Development Practices
We follow secure software development practices:
- Code reviews: all code changes require at least one peer review before merging.
- No secrets in source control: credentials, API keys, and secrets are stored in environment variables or a secrets manager — never committed to the repository.
- Dependency management: we keep dependencies updated and monitor for known vulnerabilities.
- Automated testing: we run automated tests for critical functionality.
- Type safety: the codebase uses TypeScript with strict type checking to reduce the risk of runtime errors.
Stripe Payment Security
Klicktify Never Sees Card Data
Klicktify uses Stripe to process all subscription payments. When you upgrade to a paid plan, you are redirected to Stripe's secure, PCI DSS Level 1 certified checkout. Your card number, CVV, and card details are entered directly into Stripe's systems and never pass through Klicktify's servers.
What Klicktify Stores
Klicktify stores only a tokenised payment method reference from Stripe — not your raw card data. This is the same approach used by millions of businesses worldwide and is considered PCI-compliant by design.
Stripe's Security
Stripe is PCI DSS Level 1 certified (the highest level of payment card security) and handles billions of dollars in transactions annually. For more information about Stripe's security practices, visit stripe.com/security.
Vulnerability Reporting and Responsible Disclosure
We Welcome Security Research
We believe that security researchers play a vital role in keeping the internet safe. If you discover a security vulnerability in the Klicktify platform, we encourage you to report it to us responsibly.
How to Report
Please send your report to security@klicktify.com with the following information:
- A clear description of the vulnerability and the affected component.
- Steps to reproduce the issue (please use non-destructive testing only).
- The potential impact of the vulnerability.
- Your name and contact details (optional — we will credit good-faith researchers unless you prefer anonymity).
Our Commitment
- We will acknowledge receipt of your report within 3 business days.
- We will provide an estimated timeline for remediation.
- We will not pursue legal action against good-faith researchers who follow this responsible disclosure process.
- For significant vulnerabilities, we will credit the researcher in our release notes or on our security acknowledgements page (with your permission).
Out of Scope
The following are out of scope for vulnerability reports: social engineering attacks, physical security testing, denial-of-service attacks from your own infrastructure, reports from automated scanners without manual verification, and attacks on third-party services integrated with Klicktify.
Contact
Security Questions
If you have questions about our security practices, believe you have identified a security issue, or have concerns about your account security, please contact security@klicktify.com. For general data protection enquiries, contact our PDPO at dpo@klicktify.com.