Security
How we protect your data.
A plain overview of what is in place today. We aim to be accurate rather than impressive — we do not claim to be certified or fully compliant.
In place today
- ✓Encryption in transit (HTTPS) and a strict set of browser security headers.
- ✓Passwords stored only as a strong one-way hash, never in plain text.
- ✓Two-factor authentication (2FA) for owner and manager accounts, with recovery codes.
- ✓Login and sign-up throttling to slow brute-force and abuse.
- ✓Strong tenant isolation in the database — one cafe cannot see another's data.
- ✓An append-only audit trail of key actions.
- ✓Structured log redaction for auth material, secrets and selected personal fields.
- ✓Data minimisation — we don't collect data we don't need.
Reporting a vulnerability
Found a security issue? Email security@procafe.app. We welcome good-faith reports, will not pursue researchers who act in good faith, and aim to acknowledge reports promptly. We do not run a paid bug-bounty at this stage.
If something goes wrong
If a personal-data breach is likely to put people at risk, we notify affected customers without undue delay, and the Information Commissioner's Office within 72 hours where required.
