Trust & Security — How we protect merchants and customers | IncentivPay
    Trust & Security

    Built to earn your finance team's approval.

    This page is maintained by IncentivPay to answer common security and privacy questions about the platform. It describes current, enabled controls and is not an independent certification.

    Trust shields
    Authentication
    Merchant, customer, and admin surfaces run on Supabase Auth with Google OAuth and password + email flows. Role-based access enforced via a dedicated user_roles table with SECURITY DEFINER checks.
    Data isolation
    Row-level security is enforced on every user-facing table. Merchant staff see only their restaurant's data. Customers see only their own.
    Fraud controls
    Every payout runs through multi-signal risk scoring — receipt integrity, identity verification, velocity, and geo consistency. Payouts on high-risk entries route to human review.
    Payments
    Stripe handles all card processing and issuing. IncentivPay never stores raw PAN or CVV. IP Cash spends within the network — not to a bank.
    Audit logs
    All admin actions are append-only. Every AI decision is logged with the ranking signals it used.
    Data locality
    Hosted on managed cloud infrastructure in the US and Canada. Data residency controls available on Enterprise.
    Shared responsibility

    What we control, what you control.

    IncentivPay operates the platform: authentication, encryption in transit and at rest, database security, RLS policies, and the incentive engine.

    Merchants control: campaign configuration, staff access, promotional copy, and receipts uploaded through their own POS or Shopify connection. Customers control: their account, consent preferences, and wallet activity.

    • TLS everywhere; database encryption at rest
    • Least-privilege secrets, rotated regularly
    • No PHI stored — healthcare integrations use appointment confirmation only

    Frequently asked

    Are you SOC 2 certified?+

    IncentivPay is not currently SOC 2 certified. Enterprise merchants with certification requirements can reach out at sales@incentivpay.com to discuss the roadmap.

    Are you GDPR / CCPA compliant?+

    We honor deletion and data-access requests via support@incentivpay.com. Customers can also self-serve consent controls in their account settings.

    Where can I report a security issue?+

    Email security@incentivpay.com. We respond within one business day.

    Talk to us about your security review.

    Enterprise buyers get a security questionnaire template and direct engineering access.