Security
Last updated:
Vintique uses safeguards designed to protect private account data. This page explains payment handling, access controls, and how to report a security concern.
Card credentials stay with your payment provider
With an independently operated terminal, you record payment totals in Vintique. Where a supported card integration is enabled, Vintique sends payment instructions and receives results, payment references, card brand and last four digits. The reader and payment provider handle the full card number and security code. Subscription checkout uses Stripe's hosted payment flow. Do not enter full card numbers or security codes into Vintique notes, uploads or other fields.
Payment integrations depend on your processor, reader and enabled features. Using Vintique does not itself establish PCI compliance or eligibility for a particular self-assessment questionnaire. Confirm the assessment and validation requirements for your complete setup with your acquiring bank or payment provider.
Where your data lives
Vintique's primary application storage is hosted on Amazon Web Services in the United States. We use encryption in transit and at rest and automated database backups. The third-party services we rely on, and what each one sees, are listed on our sub-processors page.
Private account data
Access controls separate private mall Workspaces and independent vendor accounts. Information and image copies you intentionally publish on a storefront are public. Our Privacy Policy explains that distinction and when authorized Vintique staff may access private data.
People see only what their role allows
Access inside a mall depends on the user's role and assigned permissions. Administrative functions require authorized access. Sensitive tax identification numbers collected for 1099 reporting are encrypted and access-restricted.
How we operate
- We use network protections and access controls to help secure the Service.
- Production access is restricted to authorized systems and personnel.
- We use review and deployment procedures to manage production changes.
- We use monitoring and alerts to help identify failures and security issues.
Reporting a security concern
If you believe you've found a security vulnerability in Vintique, please [email hidden — JS loading] with the details. Reports go straight to the founder, and we'll respond promptly. We ask that you give us a reasonable opportunity to address an issue before sharing it publicly.
Related: Privacy Policy · Sub-processors · Terms of Service