Security & Data Protection

Your trust is our top priority. Learn how we keep your data safe and secure.

πŸ”

End-to-End Encryption

All data transmitted between your device and our servers is encrypted using industry-standard TLS/SSL protocols. Your personal information, health data, and payment details are encrypted both in transit and at rest.

  • AES-256 encryption at rest
  • TLS 1.3 for data in transit
  • Encrypted database backups
πŸ”‘

Secure Authentication

We use Firebase Authentication, a battle-tested system trusted by millions of apps worldwide. Your passwords are never stored in plain text.

  • Phone number verification (OTP)
  • Apple Sign-In integration
  • Bcrypt password hashing
  • Multi-factor authentication support
πŸ›‘οΈ

Privacy by Design

We collect only the minimum data necessary to provide our services. You control what you share, and we never sell your personal or health data to third parties.

  • Minimal data collection
  • No sale of personal data
  • Granular privacy controls
  • HIPAA-aware practices
πŸ’³

PCI-DSS Compliant Payments

We partner with industry leaders (Stripe, Apple, Google) for payment processing. We never store your credit card information on our servers.

  • Stripe for web payments
  • Apple/Google for in-app purchases
  • PCI-DSS Level 1 compliance
  • Tokenized payment data
πŸ‘οΈ

Access Controls

Strict internal policies limit who can access your data. Only authorized personnel with a legitimate need can view user information, and all access is logged.

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Audit logs for all access
  • Regular access reviews
πŸ”

Regular Security Audits

We conduct regular security assessments, vulnerability scans, and penetration testing to identify and fix potential issues before they become problems.

  • Quarterly vulnerability scans
  • Annual penetration testing
  • Code security reviews
  • Third-party security audits

Infrastructure Security

CARROT is built on Google Cloud Platform (Firebase), one of the most secure and reliable cloud infrastructures in the world. Google's infrastructure provides:

Health Data Protection

Your health and fitness data is particularly sensitive, and we treat it with the utmost care:

Data Retention and Deletion

You have full control over your data:

Compliance and Certifications

πŸ”’ SOC 2 Type II (via Google Cloud)
βœ… ISO 27001 (via Google Cloud)
πŸ’³ PCI-DSS Level 1 (via Stripe)
πŸ‡ΊπŸ‡Έ CCPA Compliant
πŸ‡ͺπŸ‡Ί GDPR Ready
🍎 Apple App Store Guidelines
πŸ€– Google Play Security Standards

Incident Response

In the unlikely event of a security breach, we have a comprehensive incident response plan:

Your Security Responsibilities

Security is a shared responsibility. Here's how you can protect your account:

🚨 Report a Security Vulnerability

If you discover a security vulnerability in CARROT, please report it to us responsibly. We appreciate the security research community's efforts to keep our users safe.

Contact: security@carrotwellness.com

Please include:

We aim to respond within 48 hours. Responsible disclosure is appreciatedβ€”please allow us time to fix issues before public disclosure.

Third-Party Security

We carefully vet all third-party services we integrate with:

All third-party vendors sign Data Processing Agreements (DPAs) committing to protect your data.

Questions About Security?

If you have questions or concerns about CARROT's security practices, we're here to help:

Security Team: security@carrotwellness.com
Privacy Questions: privacy@carrotwellness.com
General Support: support@carrotwellness.com

For more information, see our Privacy Policy and Terms of Service.

Last Updated: December 10, 2025 | We continuously improve our security practices and update this page to reflect changes.