Applies to the consumer app and Partners Portal.
1. Our commitment
Protecting your data is core to NXTRUNN. We use layered technical and organizational measures to safeguard the platform. No method of transmission or storage is 100% secure, but we work continuously to protect your information and to respond quickly to issues.
2. Safeguards in place
- Encryption in transit: traffic to and within the platform is encrypted using TLS/HTTPS.
- Trusted infrastructure & subprocessors: we build on established providers — authentication (Clerk), database/storage (Supabase, Cloudflare R2), payments (Stripe / Stripe Connect) — each with their own security programs (see the Subprocessor List). Payment card data is handled by Stripe; NXTRUNN never stores full card numbers.
- Scoped access controls: access to data is restricted by authentication and least-privilege; sensitive operations run with controlled service credentials, not client-exposed keys.
- Abuse & rate-limiting protections: write/sensitive endpoints are protected by authentication checks and rate limiting (Upstash (Redis)) to mitigate brute-force, scraping, and abuse.
- Input validation: requests are validated (schema validation) to reduce injection and malformed-data risks.
- Audit & activity logging: security-relevant actions are recorded (audit/activity logs, organization security events) to support investigation and accountability.
- Error monitoring: we use Sentry for error monitoring, configured to scrub/minimize personal data in diagnostics.
- Age & access gating: the platform enforces an 18+ gate and account-level access controls.
- Encryption at rest: data stored with our infrastructure providers is encrypted at rest per those providers' standards.
3. Your role in security
- Use a strong, unique password and enable any available multi-factor authentication.
- Keep your devices and app updated; don't share credentials.
- Be cautious about what you share publicly (including precise location/check-ins).
- Report anything suspicious to legal@nxtrunn.com.
4. Responsible disclosure (security researchers)
We welcome good-faith security research. If you believe you've found a vulnerability:
- Email: legal@nxtrunn.com with details and reproduction steps.
- Please: give us a reasonable time to investigate and remediate before any public disclosure; avoid privacy violations, data destruction, service degradation, or accessing more data than necessary to demonstrate the issue.
- We commit to: acknowledge your report, work with you on remediation, and not pursue legal action against researchers who act in good faith and within this policy.
- We do not currently operate a formal paid bug-bounty program, but we appreciate and credit good-faith reports.
5. Incident response & breach notification
We maintain processes to detect, investigate, and respond to security incidents. If a breach affects your personal data, we will notify affected users and regulators as and when required by applicable law (e.g., GDPR 72-hour authority notification, and applicable U.S. state, Canadian, Australian, and Brazilian breach-notification laws).
6. Changes & contact
We may update this Statement and will revise the "Last updated" date. Security contact: legal@nxtrunn.com · general: info@nxtrunn.com.