Information Security Policy

How we maintain system confidentiality, integrity, and availability.

Last Updated: July 14, 2026

1. Policy Purpose

This policy details the security measures Mazaya employs to protect platform data. We are committed to using industry-standard practices to ensure the security and availability of our services.

2. Scope of Policy

This policy applies to: 1. Merchants. 2. Business owners. 3. Authorized staff. 4. End-customers. 5. All other platform users.

3. Security Principles

Mazaya is built on core principles: Data confidentiality, logical integrity, high availability, granular permission management, minimal data exposure, behavior monitoring, and structured incident response.

4. Security Measures

We utilize, among others: TLS/HTTPS encryption in transit, AES-256 database encryption at rest, secure account separation keys, multi-factor login sessions, real-time logging, automated backups, and systematic vulnerability updates.

5. User Responsibilities

Users must: 1. Safeguard account credentials. 2. Use secure, strong passwords. 3. Avoid sharing API keys or logins. 4. Report unauthorized access immediately. 5. Use secure devices to access the platform.

6. Incident Response

In the event of a security breach, Mazaya will act promptly to isolate the issue, mitigate data risks, restore services, and notify affected parties in compliance with applicable law.

7. Limitations

While we employ strict security measures, no digital platform is 100% secure. Mazaya is not liable for force majeure events, hardware failures, or network disruptions beyond our control.

8. Infrastructure Partners

Our services leverage secure clouds: Vercel (frontend), Convex (database & backend API), PayPlus (billing), Apple Developer (pass signing), and Google Cloud.

9. Policy Updates

Mazaya may update this security policy at any time. The online version is always the active policy.

10. Contact Us

Email: contact@mazaya.co.il | Phone: +972-58-698-3002 © All rights reserved to Mazaya.