Skip to main content

Pickleloonies · Reference

Security

How we protect your pod's data, and how to report a vulnerability.

Encryption

All traffic is served over HTTPS with HSTS and a 2-year preload policy. Data at rest in our database is encrypted by the underlying managed Postgres service (Supabase, hosted on AWS).

Access control

Every Postgres table that holds pod data has row-level security enabled. Policies are scoped to pod membership: you can only read or write rows for pods you belong to. Roles inside a pod (admin, leader, accounting, booker, member) further gate destructive actions like changing fees or approving payments. Privileged operations run through database functions that check the caller's role themselves, and none of them can be called by a signed-out visitor.

Storage buckets are similarly scoped. Avatars and pod logos live in public buckets (you choose what to upload). Chat images, pod photos and payment screenshots are stored in private buckets and served via short-lived signed URLs — never with a permanent public link.

Content Security Policy

Every response includes a Content Security Policy header that restricts which origins can load scripts, styles, images, and network connections. Violations are reported to /api/csp-report so we can detect drift early.

Third-party processors

  • Supabase — managed Postgres, Auth, Storage, Realtime and Edge Functions. Hosted on AWS in the United States.
  • Vercel — web app hosting, CDN, and edge runtime.
  • Stripe — not used yet; it will process card payments if the Pod Wallet (coming soon) launches.
  • Resend — sign-in and account email delivery.
  • Sentry — error reporting, with names and emails excluded.
  • PostHog — anonymous analytics on the public pages, with no session recording. Turned off automatically when your browser sends Global Privacy Control.

Payments

Pickleloonies only tracks who owes what. Members pay each other directly with Venmo, Zelle or cash, so no money passes through us and we never see card or bank details. A prepaid Pod Wallet is coming soon; when it launches, card details will be entered on Stripe's own checkout page and never reach our servers. Payment screenshots you upload are private to your pod's admins and accounting members and to you.

Vulnerability disclosure

If you find a security issue, email privacy@pickleloonies.com with details and a way to reproduce. We'll acknowledge within 72 hours and won't pursue legal action against good-faith research that respects user privacy and stays within the bounds of this policy.

Data export and deletion

You can ask for a copy of your data, or for it to be deleted, by emailing us. Account deletion is also available from your profile. See the Privacy Policy for retention specifics.