KissMyApp
Security & Compliance
Security
Your security and privacy are our top priorities. This page outlines our security practices and how to report vulnerabilities.
✓ Secure by default: All communications are encrypted. Your data is yours—we don't collect or sell it.
Security Practices
🔒 Encryption in Transit
All data transmitted between your device and our servers is encrypted using HTTPS/TLS 1.2+. This prevents interception by third parties.
💾 Data Storage
- Local Data: Favorites and ratings are stored on your device only, not on our servers.
- Server Data: Place information and analytics are stored in encrypted databases with restricted access.
- Backups: Regular encrypted backups ensure data isn't lost in case of hardware failure.
🔑 Authentication
Our API uses secure, rate-limited authentication. We do not store passwords for user sessions—authentication is stateless and token-based.
🛡️ Infrastructure Security
- Servers are protected by firewalls and intrusion detection systems.
- Regular security patches and updates.
- Restricted access control — only authorized personnel can access production systems.
- Monitoring and logging for suspicious activity.
🧪 Testing & Audits
- Code reviews and security testing before each release.
- Dependency scanning to identify outdated or vulnerable libraries.
- Periodic third-party security audits.
🚫 Abuse Prevention
- Rate limiting on API endpoints to prevent DoS attacks.
- Input validation to prevent injection attacks.
- Content moderation for user-submitted data (where applicable).
Third-Party Security
We partner with trusted providers:
- Google Places API: Industry-leading security and compliance (SOC 2, ISO 27001).
- Supabase (Database): Enterprise-grade PostgreSQL hosting with encryption at rest and in transit.
- Ticket Partners: Viator, Tiqets, Klook, Trip.com—each maintains their own security standards.
We regularly audit third-party integrations for security compliance.
Compliance
- GDPR: Compliant with European data protection regulations.
- CCPA: Compliant with California consumer privacy rights.
- HTTPS: All domains use HTTPS encryption.
- Privacy Policy: Clear, transparent data handling practices (see Privacy Policy).
Report a Security Vulnerability
Responsible Disclosure: If you discover a security vulnerability, please email us instead of posting it publicly. We take all reports seriously and will respond within 48 hours.
How to Report
Send a detailed report to:
Email: security@kissmyapp.org
Please include:
- A clear description of the vulnerability.
- Steps to reproduce the issue.
- The impact (what an attacker could do).
- Your contact information (name, email).
- Whether you'd like credit in a security disclosure (optional).
What to Expect
- Acknowledgment: We'll confirm receipt within 48 hours.
- Investigation: We'll investigate and determine the severity.
- Fix: For critical issues, we prioritize fixes and deploy within 30 days.
- Disclosure: We'll credit you in a security advisory (if you opt in).
✓ Safe Harbor: We will not pursue legal action against researchers reporting vulnerabilities in good faith.
Security Updates
We release security updates regularly. To stay informed:
- Check the in-app "What's New" section for update notes.
- Subscribe to our newsletter for major announcements.
- Email support@kissmyapp.org with questions.
Best Practices for Users
- Keep your app updated to receive the latest security patches.
- Use a strong browser password if you store sensitive information locally.
- Avoid public Wi-Fi when accessing apps with sensitive data (we use HTTPS, but it's good practice).
- Review partner privacy policies before clicking ticket links or signing up on third-party sites.
Questions?
If you have security concerns or questions, contact us:
Security: security@kissmyapp.org
Support: support@kissmyapp.org