cekap apps

Legal

Security Policy

Last updated: 31 July 2026

Our customers run their businesses on our software. Their sales, their students and their money are in it. This page sets out, plainly, what we do to keep that safe — and what we ask of you.

Encryption

Separating one business from another

Our products are multi-tenant: many businesses share the same system. Keeping them apart is the single most important thing we do.

Access control

Payment data

We do not store card numbers or banking credentials. Payments are processed by a licensed payment gateway on PCI-DSS compliant infrastructure. Our systems hold only a payment reference and the amount. See our Payment Policy.

Backups and recovery

Public content and abuse

Some parts of our products publish content that customers create, such as a shop's public product catalogue. To keep that safe:

If something goes wrong

If we become aware of a security incident affecting customer data we will investigate immediately, contain it, and notify affected customers — and the Personal Data Protection Commissioner where the Personal Data Protection Act 2010 requires it — without undue delay. We will tell you what happened, what data was involved and what we are doing about it.

Reporting a vulnerability

If you believe you have found a security weakness in our software, please tell us at hello@cekapapps.com with the subject line SECURITY. We will acknowledge within 2 working days and keep you updated.

Please give us a reasonable chance to fix an issue before disclosing it publicly, and do not access, alter or delete other people's data while testing. We will not pursue action against anyone who reports a genuine issue in good faith and follows this request.

What we ask of you