Security is one of our top priorities. This page outlines the main technical measures we use to protect your account, your customers’ data, and the store locator widgets you embed.

Encryption

All data sent to and from our website, admin console, and store locator widgets is encrypted in transit using HTTPS (SSL/TLS) with modern certificates. Confidential or identifiable information — including account and payment data — is also encrypted at rest across our internal and third-party managed infrastructure.

Passwords & Account Access

Passwords for the Store Locator admin panel are hashed and salted using bcrypt; we never store passwords in plain text, and our administrators do not have access to your unencrypted password. Password recovery is handled via email to your registered address only. We also use two-factor authentication to protect access to our own cloud infrastructure.

Access Control

Access to privileged systems and data is restricted to a limited number of named individuals who require it to perform specific functions, and is governed by password complexity, account lockout, and session-timeout policies aligned with industry best practice. Personnel with privileged access receive appropriate training before access is granted.

Payments

Payments are processed by Stripe, which is certified to PCI Service Provider Level 1, the most stringent level of certification available in the payments industry. We do not store your credit card details on our own systems, and all card data sent to Stripe is encrypted in transit.

Infrastructure & Availability

Our data is hosted on Amazon S3 with copies held across multiple geographically separate zones, so that a failure in one zone doesn’t take your locator offline. We use Amazon CloudFront to serve widget assets quickly worldwide and to help mitigate denial-of-service attacks.

Contact Us

If you have any questions about our security practices, or wish to report a security concern, please email us at [email protected].