Sticky
Security

Your member list is the asset. Here is how we hold it.

You are handing a vendor the phone numbers and purchase history of every regular you have. That deserves a straight answer rather than a badge wall, so this page is the controls, the data commitments, and what you can ask us for.

The infrastructure side.

Encryption in transit and at rest

Member records, order history, and message content are encrypted on the wire and on disk.

HMAC-signed webhooks, both directions

Every event we send and receive is signed, so your POS and Sticky can each verify the other. Secret rotation is supported.

Role-based access, with SSO

Budtenders, marketing managers and GMs each see only what their role needs. Single sign-on is available on Enterprise.

Replayable event log

Every integration event is logged and replayable, so you can audit exactly what was sent, to whom, and what came back from the register.

Least-privilege access controls and MFA are enforced across our own organisation, and every admin action against your account is written to an audit log.

What we do and don't do with your data.

We don't sell access to your members

We never sell, rent, lease, or otherwise disclose your customer data to third parties for commercial or marketing purposes. We don't run a brand-paid messaging marketplace, so nobody messages your customers but you. That commitment is in our privacy policy, not just on this page.

Your data leaves with you

Export your member list, balances, and history whenever you want, not just on the way out. Your data is deleted on request or at termination. You are month to month, so nothing about leaving is designed to be difficult.

What to ask for before you sign.

Security documentation and a Data Processing Agreement are available on request, and the DPA is published. If your legal or IT team has a questionnaire, send it over. If we can't answer something, we'll say so rather than write around it.