Security

Last updated: May 2026

Shopper's Mate is an MVP in development, preparing for an initial Brisbane retailer pilot. Security is being designed into the product from the start, before real retailer and customer data begin flowing in. This page describes the principles we are building around. It does not describe a certified production system, and it does not make claims about specific hosting regions, specific encryption standards or specific certifications that have not yet been implemented and verified.

1. Payment security

Card data is intended to be handled by approved payment partners and compatible external EFTPOS terminals. Shopper's Mate is not being designed to store raw card numbers, CVVs or full card-present authentication data. Retailers keep using their existing payment terminal relationships during the MVP and initial pilot.

2. Access control

The retailer platform is being designed for authenticated sessions, per-user accounts and clear separation between retailer accounts. Basic authenticated and segregated access is required for pilot operation. Granular role configuration is planned after the initial workflow. Retailers should only see their own store activity. Founder and staff access to production systems will be limited to what is needed to support the pilot.

3. Data minimisation

We are building the product to collect the minimum data needed for checkout, the shared Reward's Mate rewards ledger, digital receipts, basic inventory visibility and retailer reporting. We do not plan to collect identifiable customer purchase data for sale or for exposure to unrelated retailers.

4. Encryption

Modern web transport encryption is being used for the website. Encryption of data in transit and at rest is intended for the retailer platform. Exact standards, key management approach and hosting choices will be documented and confirmed before pilot retailers begin sending real transaction data.

5. Australian privacy expectations

We are building the product to follow Australian privacy expectations and consent principles for loyalty and marketing activity. See the Privacy Policy for how information is currently handled and how Reward's Mate product data is planned to be handled during the pilot.

6. Pilot readiness review

Before pilot retailers go live, we plan to share a written security and data-handling summary as part of the retailer agreement, including how access is granted, how data is segregated between retailers, backup and recovery expectations, and how a retailer can export or delete their data at the end of the pilot.

7. Reporting a concern

If you believe you have found a security issue with the website or want to raise a concern about how information is handled, contact us at hello@shoppersmate.com.au. We are based in Brisbane, Australia, and will respond within a reasonable timeframe.