Trust Center / WalletPassBuilder

Security and privacy overview

Review WalletPassBuilder’s compliance posture, privacy practices, security controls, and data deletion request options.

Compliance

Frameworks and technical safeguards WalletPassBuilder aligns with today.

EU-U.S. Data Privacy Framework
Pending

EU-U.S. Data Privacy Framework

UK Extension to the EU-U.S. DPF
Pending

UK Extension to the EU-U.S. DPF

CSA STAR Level 1
Verified

CSA STAR Level 1

GDPR compliant
Ready

GDPR compliant

CCPA compliant
Ready

CCPA compliant

WCAG 2.2 AA compliant
Ready

WCAG 2.2 AA compliant

TLS 1.2/1.3 encryption
Active

TLS 1.2/1.3 encryption

AES-256 encryption at rest
Active

AES-256 encryption at rest

Controls

Grouped controls with implementation status.

45 active
Infrastructure Security9 controls+

Infrastructure monitoring

Production infrastructure is monitored for availability, reliability, and security issues.

Active

Automatic backups

Automatic backups support customer data recovery and service continuity.

Active

Remote access MFA enforced

Production systems are only remotely accessible to authorized staff with multi-factor authentication.

Active

Encrypted remote access

Remote production access requires an approved, encrypted connection.

Active

Production data segmented

Customer data is never used or stored in non-production environments.

Active

Network segmentation

Network segmentation limits the blast radius of unauthorized access.

Active

Unique network authentication

Production network access requires unique credentials or authorized keys.

Active

Unique account authentication

Systems and applications require unique per-user authentication.

Active

Multi-zone infrastructure

Services run across multiple availability zones to support recovery if one is unavailable.

Active
Product Security4 controls+

Vulnerability monitoring

Formal procedures govern vulnerability management and ongoing system monitoring.

Active

Secure development practices

Software delivery follows secure development practices from implementation through release.

Active

Secrets management

Credentials, keys, and sensitive configuration are managed through a dedicated secrets manager, never checked into source.

Active

Input validation

Application inputs are validated to protect product workflows and customer data.

Active
Organizational Security6 controls+

Employee background checks

Background checks are performed for new employees.

Active

Security awareness training

Employees complete security awareness training at onboarding and at least annually.

Active

Contractor confidentiality agreements

Contractors sign confidentiality agreements at engagement.

Active

Production inventory maintained

A formal inventory of production system assets is kept up to date.

Active

Employee confidentiality agreements

Employees sign confidentiality agreements during onboarding.

Active

Asset disposal procedures

Electronic media containing confidential information is purged or destroyed per best practice.

Active
Internal Security Procedures15 controls+

Continuity and disaster recovery tested

BC/DR plans are documented and tested at least annually.

Active

Incident response plan tested

The incident response plan is tested at least annually.

Active

Access requests required

Access is granted by job role or a documented, manager-approved request.

Active

Backup processes established

Backup and recovery requirements for customer data are documented.

Active

Incident response policy established

Security and privacy incident response policies are documented and communicated.

Active

Configuration management

Configuration procedures keep production systems consistent.

Active

Management roles defined

Management oversees control design and implementation responsibilities.

Active

Service description communicated

Product and service descriptions are communicated to users.

Active

Security policies reviewed

Security policies are documented and reviewed at least annually.

Active

Support system available

Users can report failures, incidents, concerns, and complaints.

Active

Roles and responsibilities specified

Security control responsibilities are formally assigned.

Active

Data center access reviewed

Cloud provider data center access is reviewed at least annually.

Active

Development lifecycle established

A formal SDLC governs systems and technology changes.

Active

Cybersecurity insurance maintained

Cybersecurity insurance mitigates the financial impact of a disruption.

Active

Continuity communication plans

BC/DR plans include communication plans to support continuity.

Active
Data and Privacy11 controls+

Privacy policy established

The privacy policy communicates what's collected, our obligations, and how to reach us.

Active

Data retention procedures

Formal retention and disposal procedures guide secure handling of data.

Active

Privacy complaint procedures

Privacy complaints are addressed, documented, tracked, and communicated.

Active

Privacy policy available

The privacy policy is available before or when information is collected.

Active

Privacy policy reviewed

The privacy policy is reviewed when changes occur or on a regular cadence.

Active

Privacy policy maintained

The policy explains jurisdictions, rights, data categories, collection, and disclosures.

Active

Data deletion requests handled

Deletion requests are validated, tracked, and completed under applicable requirements.

Active

Continuity plans established

BC/DR communication plans support continuity if key personnel are unavailable.

Active

Continuity plans tested annually

The documented BC/DR plan is tested annually.

Active

Collection minimized

Personal data collection is limited to the minimum necessary for its purpose.

Active

PII encrypted in transit

Personal data is encrypted in transit end to end.

Active

Subprocessor list

Infrastructure, database, payment, email, and pass-delivery vendors used to operate the service.

8 listed

Cloudflare

Reverse proxy and CDN in front of all traffic to the Services.

Global

Google Cloud Platform

Application hosting, container registry, and file storage.

US

MongoDB Atlas

Database hosting and data storage.

US, EU

Stripe

Payment processing and subscription billing.

Global

Resend

Transactional email delivery.

Global

Twilio

SMS and WhatsApp pass delivery.

Global

PostHog

Product analytics and session recording, only after cookie consent where required.

EU

Apple & Google

Apple Wallet, Google Wallet, and Google Sign-In.

Global

Data deletion request

Most requests can be handled directly, without a form or a wait for a human to respond.

Have a WalletPassBuilder account?

Export or permanently delete your own account directly from Settings → My Account. Deletion is scheduled with a 14-day grace period, with an emailed link to cancel it.

Enrolled in a merchant’s loyalty program?

Ask that merchant directly — most can export or permanently erase your enrollment record themselves from their Enrolled Customers roster, without contacting us.

Can’t use either of those — or need something they don’t cover? Submit a request below and we’ll handle it directly.

How requests are handled

Requests are validated before deletion to protect account security and avoid accidental loss.

  • Deletion requests are reviewed against applicable law and any obligations to other customers.
  • Confirmed requests are flagged and processed through our privacy workflow.
  • Only the minimum information necessary for validation is collected.
  • Personal data submitted through this form is encrypted in transit.

Request deletion

Do not include passwords, payment details, or unrelated sensitive information.