Security at PoopyPuppy
Last revised June 12, 2026
Our commitment
You trust us with your home, your dogs, and your payment information. We maintain a written information security program, reviewed regularly, that protects that trust. Here is what it means for you in practice.
Payments and bank information
- All payments are processed by Stripe, a PCI-DSS Level 1 certified processor. We never store your full card or bank account number — only the last 4 digits, for display in your account.
- If you connect a bank account, the bank login happens directly between you, Stripe, and your bank on your own device. Your bank username and password never touch PoopyPuppy's systems.
- Recurring payments are only ever charged under an authorization you explicitly gave — and you can revoke it at any time.
Encryption
All traffic to and from our services is encrypted in transit (TLS 1.2+ with HSTS). Data at rest — including photos, documents, and backups — is encrypted with AES-256. Passwords are stored only as modern memory-hard hashes (argon2id), never in a readable form. Payment keys and integration credentials are themselves encrypted at rest.
Access controls
- Staff access is role-based and least-privilege: technicians, salespeople, franchise owners, and administrators each see only what their job requires, enforced on every page and action — with a second, independent layer of enforcement inside the database itself.
- Photos, check images, and authorization recordings live in private storage and are viewable only through expiring, per-request signed links tied to an ownership check — never public URLs.
- Our database accepts no connections from the public internet.
Monitoring and auditing
Every sign-in is logged with time, IP address, and device details — you can review your own recent sign-ins in the portal. Application errors are monitored continuously, with personal information scrubbed before anything is recorded. Billing state is reconciled against our payment processor nightly, so discrepancies surface fast.
Backups and resilience
Customer data is backed up nightly, encrypted, to storage independent of our application servers, and our full production environment can be rebuilt from version-controlled configuration.
Reporting a security issue
If you believe you have found a security vulnerability in any PoopyPuppy service, please email support@poopypuppy.com with SECURITY in the subject line. We read these promptly, we appreciate good-faith reports, and we will keep you informed as we investigate and fix.
Want more detail?
Our full written information security program (aligned to the NIST Cybersecurity Framework) is available to partners, processors, and insurers on request via the email above. For what we collect and how we use it, see our Privacy Policy.
