Merch Madness
Security

Last updated: February 13, 2026

🔒
We take the security of your data, designs, and earnings seriously. Here is how we protect what matters to you.

1. Payment Security

All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor — the highest level of certification in the payment industry.

What this means

We never see, store, or have access to your full credit card numbers or bank account details. All sensitive financial data is handled directly by Stripe.

Creator payouts

Stripe Connect Express handles creator identity verification and banking details. Your payout information is encrypted and stored by Stripe, not by us.

PCI DSS Level 1 Stripe Connect SOC 2 Compliant

2. Data Encryption

In transit

All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). This applies to every API call, login request, design upload, and page load.

At rest

Our database is hosted on encrypted infrastructure. Passwords are hashed using bcrypt with a strong work factor — we cannot read your password, and neither can anyone else.

Design files

Your designs are stored on secure cloud infrastructure with access controls that restrict who and what systems can access them.

3. Authentication and Sessions

4. Infrastructure

5. AI and Design Data

6. Third-Party Security

We carefully select partners who maintain high security standards:

7. Access Controls

8. Incident Response

In the unlikely event of a security breach that affects your data, we will:

9. What You Can Do

10. Reporting a Vulnerability

If you discover a security vulnerability, please report it responsibly to support@merchmadness.app. We appreciate the security community's efforts and will acknowledge valid reports promptly.