Security
Effective date: June 30, 2026
At Omniral Media LLC (which operates Benchry), protecting shop and customer data is core to the Service. This page summarizes the security practices we follow. It is provided for transparency and is not a contractual warranty; specific commitments, if any, are set out in your agreement with us.
Infrastructure
- The Service runs on reputable cloud infrastructure providers, with physical and network security maintained by those providers.
- We separate environments (development, staging, production) and restrict production access.
Encryption
- Data is encrypted in transit using TLS/HTTPS.
- Sensitive credentials (such as account passwords) are stored using strong one-way hashing, never in plaintext.
Authentication and access control
- Access to shop accounts is protected by per-shop authentication and session management.
- Role-based access controls and plan-based permissions limit what each user can see and do.
- Internally, we follow the principle of least privilege and limit administrative access to those who need it.
Tenant isolation
Benchry is multi-tenant. Each shop’s data is logically separated and scoped to that shop, and every request is resolved to the correct tenant before data is returned.
Payment security
We do not store full payment card numbers. Card data is handled by PCI-DSS-compliant payment processors (Stripe, Square, Clover, and PayPal). We retain only non-sensitive transaction metadata.
Monitoring, logging, and auditing
- We maintain application logging and error monitoring to detect and diagnose issues.
- Sensitive actions (such as voids, refunds, status changes, and configuration changes) are recorded in an audit trail.
Backups and resilience
We maintain backups of critical data and take measures to support recovery. We encourage shops to export important data periodically.
Vulnerability reporting (responsible disclosure)
We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email [email protected] with details and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before public disclosure, and do not access or modify data that isn’t yours.
Incident response
We maintain procedures to investigate and respond to suspected security incidents and will notify affected parties as required by applicable law.
Your responsibilities
Security is shared. Use strong, unique passwords, protect your login credentials, manage staff access appropriately, and promptly remove access for departed staff. Notify us at [email protected] of any suspected unauthorized access.
Contact
Omniral Media LLC — [email protected]