Security is not
an afterthought
We handle loyalty data for Malaysian businesses and their customers. This page explains exactly how we protect that data — no marketing language, no hand-waving.
Encryption in transit and at rest
All data transmitted between your browser and Klicktify's servers is encrypted using TLS 1.2 or higher. Data stored in our database is encrypted at rest by our hosting provider, Neon (Lakebase Postgres). Payment card data is handled exclusively by Stripe, which is PCI DSS Level 1 certified — we never handle or store raw card numbers.
Your data is yours
We collect only the data we need to run the loyalty programme: member name and email (optional), check-in history, and points balance. We do not sell your data, share it with third parties for marketing purposes, or use it for any purpose other than running Klicktify. Members can delete their own account from the settings page. To request access to, correction of, or porting of your personal data, contact us at hello@klicktify.com. See our PDPA notice for full details.
Infrastructure
Klicktify is hosted on Neon (Lakebase Postgres) with S3-compatible object storage. Neon provides automated database backups. Payment processing is handled by Stripe, which is independently PCI DSS Level 1 certified. We do not operate a 24/7 monitoring or incident response service; production incidents are handled during business hours.
Access control
Internal access to customer data is restricted to authorised team members who require it for support or engineering purposes. Merchant accounts are strictly isolated — a merchant can only see their own tenant's members, transactions, and settings. Member passwords are hashed; we do not store plaintext credentials.
Vulnerability management
We track and apply security updates to our dependencies as part of regular development. Automated dependency vulnerability scanning is not yet formally configured in this codebase. If you find a security issue, please contact security@klicktify.com — we will respond as quickly as possible.
Incident response
If a security incident affects member or merchant data, we will notify affected parties as required by Malaysia's Personal Data Protection Act (PDPA). Our commitment is to communicate promptly and honestly. For full incident response procedures, see /legal/security.
Compliance snapshot
Measures currently in place. Certifications or practices not listed here have not been verified or achieved. For the full technical and legal detail, see /legal/security.
| Measure | Status |
|---|---|
| TLS 1.2+ encryption | Implemented |
| PCI DSS (via Stripe) | Certified |
| Automated database backups (Neon) | Implemented |
| Tenant data isolation | Implemented |
| Password hashing (bcrypt/argon) | Implemented |
Responsible disclosure
If you believe you have found a security vulnerability in Klicktify, please email us at security@klicktify.com with details. We ask that you:
- Give us reasonable time to respond and fix before disclosing publicly
- Avoid accessing or modifying data beyond what is necessary to demonstrate the vulnerability
- Not exploit the vulnerability for any reason, including testing scalability
- Act in good faith and not extortionate
This page was last reviewed in October 2026. Security practices are updated as the product evolves. For the full technical and legal detail, see /legal/security. For specific security questions, contact security@klicktify.com.
Questions about your data?
If you want to export your data, delete your account, or understand exactly what we store, reach out.