Vigente desde el 22 de julio de 2026 · Última actualización: 22 de julio de 2026
Este documento se proporciona en inglés. La traducción al español se publicará tras la revisión legal; la versión en inglés prevalece.
SimpleStay maintains safeguards designed to protect the confidentiality, integrity, and availability of information.
1. Cloud Infrastructure
The Platform is operated using reputable cloud providers, including Vercel and Supabase or comparable providers.
2. Encryption in Transit
Communications between users, the Platform, and trusted providers are protected using TLS or comparable encrypted protocols.
3. Authentication
We use modern authentication standards, including OAuth 2.0 and secure authentication providers. Administrative access is restricted according to role and business need.
4. Database Security
Application data is stored in managed cloud databases with authentication, access restrictions, logging, and provider security controls.
5. Payment Security
Stripe handles card processing, bank details, payouts, and identity verification. SimpleStay generally does not store complete payment-card or bank-account credentials.
6. Email Security
Business email is hosted through Google Workspace or comparable enterprise email services.
7. Monitoring
We monitor system health, errors, availability, suspicious activity, and security-relevant events.
8. Backups
Critical data is backed up daily where appropriate. Backups support recovery and continuity, but restoration times are not guaranteed.
9. Incident Response
SimpleStay maintains an incident-response team and procedures for detection, containment, investigation, recovery, documentation, and legally required notification.
10. Access Control
Access to production systems is limited to authorized personnel and providers using least-privilege principles.
11. Responsible Vulnerability Disclosure
Security researchers may report suspected vulnerabilities to:
[email protected]
Subject: “Security Vulnerability Report” Include:
- a clear description;
- affected URL, feature, or service;
- reproducible steps;
- potential impact;
- supporting evidence; and
- contact information.
Researchers must:
- avoid accessing, changing, downloading, or deleting data that is not their own;
- avoid service disruption, denial-of-service, spam, social engineering, physical intrusion, and privacy violations;
- stop testing and notify us if sensitive data is encountered;
- provide reasonable time for investigation and remediation before public disclosure; and
- comply with applicable law.
A report does not create a right to payment. No bug bounty exists unless separately announced in writing. We will make reasonable efforts to acknowledge good-faith reports, investigate credible issues, and communicate status when appropriate.
12. No Absolute Guarantee
No technology is completely secure. This Policy describes safeguards and commitments, not an absolute warranty.
13. Contact
[email protected]
Subject: “Security Policy Inquiry”