1.Security overview
We design WITHINFEED with security in mind and use administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle. No system is perfectly secure, but we work to reduce risk across accounts, payments, and infrastructure.
In plain English
2.Account protection
Password handling
Passwords are never stored in plain text. They are stored as salted one-way hashes, so we cannot see your password. We encourage strong, unique passwords.
Role-based access
The platform enforces role-based access (Creator, Creative, Brand, Admin). Users only see the data appropriate to their role, and brand workspaces are scoped so brands access their own campaign data.
Admin controls
Administrative functions are restricted to authorized WITHINFEED / Second Nature staff and are gated behind authentication and role checks.
3.Payment security
- Subscriptions, Access Pass authorizations, and captures are processed by Stripe, a PCI-DSS-certified payment processor.
- We do not store full payment card numbers on our systems.
- Access Pass authorization and capture records store transaction references and amounts — not raw card data.
- Creator and creative payout details you provide (such as W-9, Zelle, or Venmo) are handled as confidential information.
4.Encryption and secure handling
- Data is transmitted over encrypted connections (HTTPS/TLS).
- Uploaded files and media are stored with access-controlled cloud storage.
- We follow data-minimization principles — collecting and retaining what is needed to operate the services.
- Internal access to personal data is limited to staff who need it to do their jobs.
5.Monitoring, logging, and audit
We maintain logging and monitoring to help detect and investigate suspicious activity, and we continue to mature our audit and access-review practices as the platform scales.
6.Incident response
We maintain an incident-response approach to investigate, contain, and remediate security events. Where required by law and our agreements, we will notify affected users and authorities of incidents that materially affect personal data.
7.Data retention and deletion
We retain personal data only as long as needed to operate the services and meet legal, tax, and accounting obligations, then delete or de-identify it. You can request deletion of your account and associated data, subject to information we must retain. See the Privacy Policy for details.
8.Vendor and service-provider management
We use reputable service providers for hosting, storage, payments, analytics, and communications, and we require them to protect data under contractual confidentiality and security obligations. We evaluate vendors for appropriate security practices.
9.Your responsibilities
- Use a strong, unique password and keep your credentials confidential.
- Enable available account-security features and keep your devices secure.
- Be cautious of phishing — WITHINFEED will never ask for your password by email or message.
- Notify us promptly of any suspected unauthorized access.
10.Reporting a security issue
If you discover a vulnerability or suspect a security problem, please report it responsibly to legal@withinfeed.com or support@withinfeed.com. We appreciate good-faith reports and will work to address valid issues promptly.
