Data Security Statement
How CoffeeCanz protects your personal information, payment data, and account security.
Last updated: June 2026
1. Our Security Commitment
CoffeeCanz takes the security of your personal information seriously. We implement industry-standard technical, administrative, and physical safeguards to protect your data from unauthorized access, disclosure, alteration, and destruction.
While no system is completely immune to threats, we continuously monitor and improve our security posture to protect the trust you place in us.
2. Data Encryption
In Transit: All data transmitted between your device and the CoffeeCanz platform is encrypted using TLS 1.2 or higher. This includes login credentials, deal claims, payment information, and personal profile data.
At Rest: Sensitive data stored in our databases is encrypted using AES-256 encryption. This includes personal information, account credentials, and transaction records.
3. Payment Processing Security
CoffeeCanz does not store your full payment card number, CVV, or expiration date on our servers. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of certification available in the payments industry.
When you enter payment information on CoffeeCanz, it is transmitted directly to Stripe's secure servers. CoffeeCanz receives only a tokenized representation of your payment method for future transactions.
4. Account Security
We take several measures to secure your account:
- Password hashing — Passwords are hashed using bcrypt before storage; we never store plain-text passwords
- Session management — Sessions expire automatically after periods of inactivity
- Secure authentication tokens — JWT-based authentication with expiration controls
- Rate limiting — Login attempts are rate-limited to prevent brute-force attacks
- Suspicious activity detection — Unusual login patterns trigger alerts and account protections
5. Data Storage & Location
CoffeeCanz stores data on secure cloud infrastructure within the United States. Our infrastructure providers maintain their own comprehensive security certifications including SOC 2 Type II compliance.
6. Access Controls
Access to your personal data within CoffeeCanz is restricted on a need-to-know basis:
- Employee access to production data requires authentication and authorization
- All internal data access is logged and audited
- Administrative access is protected by multi-factor authentication
- Vendors and merchants only see aggregate performance data — not individual member information
7. Security Testing
CoffeeCanz conducts regular security reviews including:
- Periodic vulnerability assessments
- Dependency scanning for known security vulnerabilities
- Input validation to prevent SQL injection and XSS attacks
- API security testing
8. Incident Response
In the event of a data breach or security incident that affects your personal information:
- We will investigate and contain the incident as quickly as possible
- Affected users will be notified within 72 hours if required by law
- We will work with law enforcement and regulatory authorities as appropriate
- We will provide guidance on steps you can take to protect yourself
9. Your Role in Security
You can help protect your account by:
- Using a strong, unique password for your CoffeeCanz account
- Not sharing your login credentials with others
- Logging out when using shared or public devices
- Reporting suspicious activity or unauthorized access immediately
- Keeping your contact email address current for security alerts
10. Third-Party Security
CoffeeCanz integrates with trusted third-party services (Stripe, Twilio, analytics providers). These services are selected based on their security practices and compliance certifications. We review third-party security commitments periodically.
11. Report a Security Issue
If you discover a security vulnerability or believe your account has been compromised, please contact us immediately:
Security email: security@coffeecanz.com
We investigate all reported security issues and respond within 1 business day for urgent matters.