Legal
Security Policy
Last updated: 31 July 2026
Our customers run their businesses on our software. Their sales, their students and their money are in it. This page sets out, plainly, what we do to keep that safe — and what we ask of you.
Encryption
- All traffic to our services is encrypted with HTTPS/TLS. Plain HTTP is redirected, never served.
- Data is encrypted at rest by our infrastructure provider.
- Passwords are never stored in readable form — only as a salted cryptographic hash. Nobody at CekapApps can read your password.
Separating one business from another
Our products are multi-tenant: many businesses share the same system. Keeping them apart is the single most important thing we do.
- Every business gets its own address, and the account is resolved from that address on the server — never from anything the browser can set.
- Isolation is enforced a second time in the database itself, using row-level security, so a query cannot return another business's rows even if application code were wrong.
- Uploaded files are stored under per-business keys and served only through checks that confirm the requester is entitled to them.
Access control
- Access to production systems is limited to those who need it, protected by strong authentication.
- Administrative actions are recorded in an audit log.
- We do not access customer business data except where necessary to investigate a fault or a support request you have raised, or where the law requires it.
- Within your own account, you control who has access and what they can do.
Payment data
We do not store card numbers or banking credentials. Payments are processed by a licensed payment gateway on PCI-DSS compliant infrastructure. Our systems hold only a payment reference and the amount. See our Payment Policy.
Backups and recovery
- Automated daily backups, retained on a rolling basis.
- You can export your own data at any time, in a portable format — it is your data and you should never be locked in.
- We maintain a documented recovery procedure and test restores.
Public content and abuse
Some parts of our products publish content that customers create, such as a shop's public product catalogue. To keep that safe:
- Images are screened automatically before they can appear publicly.
- Every public page carries a "report this page" link that anyone can use, with no account needed.
- We can take down an individual page or an entire catalogue at short notice.
If something goes wrong
If we become aware of a security incident affecting customer data we will investigate immediately, contain it, and notify affected customers — and the Personal Data Protection Commissioner where the Personal Data Protection Act 2010 requires it — without undue delay. We will tell you what happened, what data was involved and what we are doing about it.
Reporting a vulnerability
If you believe you have found a security weakness in our software, please tell us at hello@cekapapps.com with the subject line SECURITY. We will acknowledge within 2 working days and keep you updated.
Please give us a reasonable chance to fix an issue before disclosing it publicly, and do not access, alter or delete other people's data while testing. We will not pursue action against anyone who reports a genuine issue in good faith and follows this request.
What we ask of you
- Use a strong, unique password and do not share your login.
- Give staff their own users rather than sharing one account.
- Remove access for people who leave.
- Tell us immediately if you think your account has been compromised.