Security
Last updated: September 1, 2026. This page describes current operational practices. It is not a certification, audit report, or legal advice.
Practices
- Traffic to the website, API, and apps is served over HTTPS.
- Production session cookies are marked Secure.
- Application access is authenticated; sensitive actions can require MFA enrollment.
- Full payment card numbers are not stored on VIPvybz systems. Stripe, Apple, and Google process cards under their own terms.
- We do not use advertising pixels or third-party marketing analytics scripts on vipvybz.com. The pro portal on online.vipvybz.com loads a Google Ads conversion tag to measure professional sign-up.
- We do not sell personal data or train machine-learning models on user messages, bookings, or voice. We do not send voice recordings to model providers.
We do not currently hold ISO 27001 or SOC 2 certification. Privacy rights, retention, and deletion are described in our Privacy Policy.
Hosting
The VIPvybz API, database, and related AWS services run in us-east-1 (United States). SMS via AWS SNS, when that provider is enabled, also uses us-east-1.
Subprocessors
These organizations process personal data on our behalf or as payment/app-store controllers, as of the date above. We will update this table and the date when the list changes.
| Provider | Purpose | Region (typical) |
|---|---|---|
| Amazon Web Services | Application hosting, database, object storage, optional SMS (SNS) | us-east-1 |
| Stripe | Connect card payments, web billing, Terminal / Tap to Pay, gift-card settlement | United States / Stripe regions |
| Apple | In-app purchases and App Store billing (merchant of record) | Apple regions |
| Google Play billing; Firebase Cloud Messaging and App Check; optional Calendar and Meet when you connect them | Google regions | |
| Google Ads | Conversion measurement on the online pro portal (tag AW-18395983341) | Google regions |
| RevenueCat | Subscription status and receipt validation | United States / RevenueCat regions |
| Sentry | Application error and crash reports | Sentry regions |
| Cloudflare Turnstile | Bot check on public booking and login | Cloudflare edge |
| Email (configured SMTP) | Transactional mail (confirmations, invites, notices) | Depends on the mail host we configure |
| Twilio | Optional SMS when that provider is enabled | Twilio regions |
| Microsoft | Optional Outlook / Teams calendar and meetings when you connect them | Microsoft regions |
| Zoom | Optional video meetings when you connect Zoom | Zoom regions |
| HubSpot, Mailchimp | Optional CRM sync when a professional connects them | Provider regions |
| Zapier, Make | Optional automations when a professional connects them | Provider regions |
Apple, Google, and Stripe act as independent controllers for the payments they process. Calendar, video, CRM, and automation tools receive data only after a professional or user connects that integration.
Report a security issue
If you believe you have found a vulnerability or a data incident, contact us through the contact form or the email listed in the app. Please do not include full card numbers or passwords in the report.