Security Policy

Reporting a vulnerability

We take security seriously. If you find a vulnerability in CartGain, please report it privately to security@cart-gain.com. Please include: the affected endpoint, steps to reproduce, and impact. We commit to a prompt response (within 72 hours) and will never take legal action against good-faith researchers.

Our safeguards

  • All traffic encrypted in transit (TLS) — HTTPS only, via Cloudflare + Vercel.
  • Customer data encrypted at rest (Supabase managed Postgres; secrets AES-256-GCM).
  • Row-level security (RLS) enabled on all database tables.
  • Strict access logging with PII redaction for every protected-data access.
  • Automatic data retention — cart PII anonymized after 90 days; logs after 180 days.
  • Rate limiting on authentication and public endpoints.
  • Secrets stored only in environment variables; never in the repository.
  • Bots blocked at the edge (Bot Fight Mode, AI-bot blocking).

Sub-processors

  • Vercel — hosting
  • Supabase — database
  • Cloudflare — CDN/DNS/security
  • Resend / SMTP relay — transactional email
  • OpenAI — AI negotiation model

Data breach handling

In the event of a breach we will: contain and fix immediately, rotate affected secrets, notify affected merchants within 72 hours, and notify authorities where legally required. Full details in our internal incident-response policy.

Questions? Privacy Policy · Data Processing Agreement · Terms of Service

Last updated: 2026-08-03