Security
Last updated on 7 Oct 2026
We recognise the importance of excellent security practices. This document explains how your data, and your customers’ data, is protected. For the full detail on what we collect and why, see our Privacy Policy and Data Processing Agreement.
General security practices
- Access to servers, source code, and third-party tools are secured with two-factor authentication whenever possible.
- We use strong, unique, and randomly-generated passwords.
- Automated security vulnerability detection tools alert us when app dependencies have known security issues. Patches are applied and deployed promptly.
- Production data never leaves the secure host. I.e. never copied to external devices such as laptops.
Infrastructure and encryption
Leal runs on servers in the EU. The application runs on Hetzner servers, the database is PlanetScale Postgres in an EU region, and uploaded images (logos, card artwork) are stored in Cloudflare R2.
- All traffic to Leal is encrypted in transit with TLS.
- Database connections are encrypted and certificate-verified, and PlanetScale encrypts data at rest.
- Passwords are stored as one-way hashes, never in plain text.
What kind of data we hold
About you (the store owner). When you sign up we collect the minimum needed to set up your account: your name, email address and password. If you upgrade, billing is handled by Stripe (see below).
About your customers. When shoppers join your loyalty programme, Leal stores the details your sign-up form asks for (such as name, email, phone number and birthday) along with their stamps, rewards and wallet pass. We hold this on your behalf: you control it, and we only use it to run your loyalty programme. Our Data Processing Agreement covers it.
Payment information
Premium account upgrades are handled securely by our third-party payment processor, Stripe (https://stripe.com/privacy). Leal does not store card details.
Who we share information with
We don’t sell personal information, and we never share it with anyone for their own marketing.
Running Leal does mean some trusted providers process data on our behalf, for example our hosting, database and email delivery providers, and Apple and Google to deliver wallet passes. They can only use it to provide their service to us. The providers that handle your customers’ data are listed in the subprocessor list.
We use Google Analytics, and Google Ads and Meta conversion tags, on tryleal.dev and in the Leal dashboard to understand how the product is used and to measure our own advertising. These are not on the sign-up pages your customers use to join your loyalty programme, and your customers’ details are never sent to them. Our Privacy Policy explains this in full.
How do I report a potential vulnerability or security concern?
Please email [email protected] if you have any concerns.
Further questions?
Great! Please contact us at [email protected], and we’ll happily update this doc.