Skip to content

Legal

Data security

The controls protecting creator addresses, supporter payments and everything in between.

Last updated August 2026

01Encryption

  • All traffic is served over TLS 1.3. Plain HTTP requests are redirected.
  • Data is encrypted at rest on our hosting provider's managed storage.
  • Passwords are stored as salted hashes and are never recoverable in plain text.

To be drafted

  • Confirm the hashing algorithm and work factor, and set a review cadence.
  • Decide whether delivery addresses get application-level encryption on top of disk encryption.

02Address isolation

  • Delivery addresses are stored separately from public profile data.
  • A supporter's session can never resolve a creator's address; the join happens only inside the fulfilment system.

To be drafted

  • Document the access-control boundary and have it independently reviewed.
  • Define who on the team can read an address, under what approval, and how it is logged.

03Payments

  • Card details are handled entirely by a PCI-DSS compliant processor.
  • Card numbers never reach TackNote servers and are not stored by us.

To be drafted

  • Name the processor and link its compliance attestation.

04Access control and monitoring

To be drafted

  • Require SSO and multi-factor authentication for all staff accounts.
  • Define log retention, alerting thresholds and who is on call.
  • Set the schedule for access reviews and offboarding checks.

05Backups and recovery

To be drafted

  • Set backup frequency, retention and encryption.
  • Agree the recovery point and recovery time objectives, and test restores on a schedule.

06Reporting a vulnerability

  • Report security issues to security@tacknote.xyz. We will acknowledge every report.
  • We will not pursue legal action against good-faith research that respects user privacy.

To be drafted

  • Publish the full disclosure policy, scope and response times.
  • Decide whether to run a bug bounty and set reward bands.

07Certifications

To be drafted

  • Decide whether to pursue SOC 2 Type II or ISO 27001, and by when.
  • Do not claim any certification on this page until an auditor has issued the report.

Questions about this document?

Write to legal@tacknote.xyz and a human will come back to you.