Legal Center

Security Policy

Version 1.0 · Last updated 2026-10-05

1. Security Commitment

Cater Market is committed to protecting your account, your orders, and your payment information. This policy describes the safeguards we apply and the security expectations we have of our users and partners.

2. Payment Security

Cater Market never stores full credit card numbers, CVV codes, or Apple Pay or PayPal credentials. All payment instruments are tokenized by our payment provider. Secret API keys are never exposed in frontend code. Payments are verified server-side and webhooks are signature-verified. Idempotency keys prevent duplicate charges and duplicate refunds.

3. Authentication & Passwords

Passwords are never stored in plain text. We use industry-standard secure password hashing provided by the platform authentication service. Two-factor authentication is available for users who want an additional layer of account security.

4. Encryption

Data in transit is encrypted using TLS. Sensitive files uploaded for verification, refund evidence, or reviews are stored privately and access follows the permissions defined in this policy.

5. Role-Based Access Control

Access to data is restricted by role. Customers, restaurants, caterers, and drivers each see only the information appropriate to their role. Administrative access is further divided by admin level so that not every employee has full administrative powers. Sensitive functions such as refunds, payment information, and account restrictions require appropriate permissions.

6. Audit Logs

We maintain secure audit records for important actions including policy acceptance, login and security changes, refund decisions, payment changes, restaurant order changes, and administrative actions. Audit logs are not editable by ordinary users.

7. Security Notifications

We notify you when important account activity occurs, including password changes, password resets, new device logins, email or phone changes, payment method changes, and suspicious login detection. Each notification tells you what happened and how to secure your account if the activity was not authorized.

8. Data Minimization

Only information reasonably required to operate the platform is collected. Partners and drivers receive only the information they need to fulfill their role, as described in the Privacy Policy.

9. Reporting Security Issues

If you believe your account has been compromised or you suspect a security vulnerability, report it immediately through the in-app Help Center or the Report Suspicious Activity tool in Settings. We investigate credible reports promptly.

10. Partner Security

Caterers and drivers must complete identity and, where applicable, background and document verification before participating. Partners are responsible for safeguarding their own account credentials and for the security of any device used to access Cater Market.

11. Limitations

No system is perfectly secure. While we apply strong safeguards, we cannot guarantee absolute security. This policy describes our practices, not a warranty, and does not limit any rights you may have under applicable law.

Questions? Contact Cater Market support through the in-app Help Center.

All policies →