Reporting a vulnerability
We take security seriously. If you find a vulnerability in CartGain, please report it privately to security@cart-gain.com. Please include: the affected endpoint, steps to reproduce, and impact. We commit to a prompt response (within 72 hours) and will never take legal action against good-faith researchers.
Our safeguards
- All traffic encrypted in transit (TLS) — HTTPS only, via Cloudflare + Vercel.
- Customer data encrypted at rest (Supabase managed Postgres; secrets AES-256-GCM).
- Row-level security (RLS) enabled on all database tables.
- Strict access logging with PII redaction for every protected-data access.
- Automatic data retention — cart PII anonymized after 90 days; logs after 180 days.
- Rate limiting on authentication and public endpoints.
- Secrets stored only in environment variables; never in the repository.
- Bots blocked at the edge (Bot Fight Mode, AI-bot blocking).
Sub-processors
- Vercel — hosting
- Supabase — database
- Cloudflare — CDN/DNS/security
- Resend / SMTP relay — transactional email
- OpenAI — AI negotiation model
Data breach handling
In the event of a breach we will: contain and fix immediately, rotate affected secrets, notify affected merchants within 72 hours, and notify authorities where legally required. Full details in our internal incident-response policy.
Questions? Privacy Policy · Data Processing Agreement · Terms of Service
Last updated: 2026-08-03