1. Security Overview
As a multi-tenant Software-as-a-Service (SaaS) platform built for independent restaurants, Yumzip is committed to protecting the data, reliability, and daily operations of our users. This page outlines the practical security measures, technical standards, and shared practices we use to keep our platform running safely. Our goal is to build a trusted environment where restaurants can confidently run their websites, menus, and ordering systems.
2. Platform Security
The Yumzip platform securely isolates each restaurant's digital storefront within a shared cloud environment. We design our systems to ensure your business data remains private and protected.
- Restaurant Account Isolation: Our software uses built-in data separation controls. Database requests are strictly limited to each specific restaurant's account, preventing other users or storefronts from viewing or accessing your private data.
- Data Encryption in Transit: All web traffic traveling to and from Yumzip websites, admin dashboards, and digital menus is automatically encrypted using Hypertext Transfer Protocol Secure (HTTPS) and modern Transport Layer Security (TLS) standards.
- Security Monitoring: We use automated web firewalls to analyze incoming traffic. These firewalls help identify, block, and mitigate common online threats, automated bot attacks, and malicious requests before they affect the platform.
3. Data Protection & Access Controls
We use industry-standard security practices to protect business information, database backups, and configuration settings across our cloud systems.
- Data Storage Security: Data stored within our application databases and platform file repositories is protected using standard cloud encryption tools.
- Secure Password Handling: User login credentials and account identifiers are securely hashed and salted using modern cryptographic algorithms before they are stored. We never save or log cleartext passwords.
- Internal Access Control: Access to Yumzip's internal administrative tools is strictly restricted to authorized team members who require it to perform their core job responsibilities.
4. Payment Security & Financial Disclaimers
Yumzip operates strictly as a technology software provider. To ensure maximum safety for your customer transactions, our platform is designed to stay completely separated from the flow of payment funds.
Important Business Model Notice
Yumzip is NOT a payment processor, payment aggregator, merchant of record, escrow service, or financial institution. Yumzip does not collect, receive, hold, transfer, settle, clear, or manage restaurant or customer funds. All revenue from your orders goes directly to your own account.
- No Financial Card Storage: Yumzip does not collect, store, process, or transmit credit card numbers, CVVs, or banking details.
- Secure Third-Party Integrations: Online payments are handled through direct integrations with third-party payment service providers. When customers order, their card information is securely handled by your chosen provider through secure scripts, bypassing Yumzip systems completely.
- Securely Stored Credentials: The API keys and connection credentials you use to link your storefront to your third-party payment service provider are encrypted and stored securely within our infrastructure.
5. Infrastructure Monitoring & Threat Detection
Our platform runs on reliable cloud hosting providers that include automated tracking tools to maintain high availability and prevent downtime.
- Activity Logging: Core system actions, errors, and configurations generate automated event logs. These logs help our engineering team review platform health and investigate unusual behavior.
- System Backups: We perform regular automated backups of platform data and store them securely within our cloud infrastructure to allow for system recovery in the event of an outage.
- Scalable Architecture: Our cloud systems are built to scale dynamically, helping your digital storefront remain active and responsive during peak ordering hours.
6. Software Security & Updates
We routinely review our code base and external software tools to keep the Yumzip platform stable, modern, and secure.
- Dependency Reviews: We regularly check the external code libraries used by our software to identify and update any components with known vulnerabilities.
- Testing and Deployment: New features, optimizations, and bug fixes go through a controlled testing pipeline before they are deployed to our live production environment.
- Separate Testing Environments: Our development and testing workspaces are kept entirely separate from live restaurant storefronts, ensuring software updates are vetted before release.
7. Account & Access Management
Account security works best when the platform and the user work together. We provide features to help you protect your restaurant admin dashboard.
- Secure Sessions: We use secure, modern browser cookie attributes to protect active dashboard sessions and protect users against web session hijacking attempts.
- Password Standards: The platform encourages restaurant owners and staff to use strong, unique passwords when setting up or resetting their accounts.
- Inactivity Session Expirations: Administrative dashboard logins are set to log out automatically after periods of prolonged inactivity to prevent unauthorized physical access on shared devices.
8. Security Incident Response
If a security issue or unexpected platform failure occurs, Yumzip follows an established response procedure to limit downtime and fix the problem quickly.
| Phase | Action Items & Systemic Commitments |
|---|---|
| Isolation & Containment | Identify the problem, restrict affected system paths, and revoke compromised access tokens to stop further impact. |
| Fix & Resolution | Investigate log files to find the cause, apply necessary software patches, and confirm normal system behavior. |
| Communication | Notify affected restaurant accounts if a confirmed security incident impacts their specific business operations. |
10. Responsible Vulnerability Disclosure
Yumzip welcomes feedback from independent security researchers and IT professionals who help improve web security. If you discover a security flaw or vulnerability on our platform, please report it to us responsibly.
Submission Standards:
- Email your detailed technical findings directly to [email protected].
- Provide clear steps to reproduce the issue, including relevant URLs and request examples.
- Do not attempt to view, modify, or download data belonging to other restaurants or users.
- Give our team a reasonable timeframe to review and resolve the issue before sharing any details publicly.
We appreciate your cooperation in keeping our platform safe and will review valid reports as quickly as possible.
11. Contact Information
If you have any questions regarding our security practices, platform architecture, or compliance, please reach out to our team:
- Security Reports: [email protected]
- Compliance Concerns: [email protected]
- General Support Queries: [email protected]