Security at ZOE Connect
This page is maintained by ZOE Connect to answer common security and privacy questions about our service. It describes the controls that are active today — it is not an independent audit or certification of ZOE Connect.
Controls in place
256-bit SSL/TLS
Every page and payment is served over HTTPS with TLS 1.2+ and 256-bit encryption.
PCI DSS Level 1 payments
Card details go straight to Stripe, a PCI DSS Level 1 provider. We never see or store them.
Protected accounts
Passwords are hashed, sessions are token-based, and your data is isolated per account.
Verified delivery
Top-ups and gift cards are delivered through vetted licensed distribution partners.
Compliance & certifications
An independent SOC 2 examination of our security controls has been completed; the report is available to customers on request under NDA. ISO/IEC 27001 is listed as a program we are working toward — ZOE Connect is not ISO 27001 certified today.
SOC 2
Audit completedAn independent SOC 2 examination of our security controls has been completed. The report is available to customers on request under NDA.
PCI DSS Level 1
Via StripeCard data is handled entirely by Stripe, a PCI DSS Level 1 certified service provider. ZOE Connect never stores card numbers.
ISO/IEC 27001
Working towardWe are aligning our information security management practices with the ISO/IEC 27001 framework. ZOE Connect is not ISO 27001 certified today.
Encryption in transit
Every request to ZOE Connect is served over HTTPS. Our hosting provider terminates TLS 1.2+ using modern cipher suites with 256-bit symmetric encryption, and certificates are issued and renewed automatically. You can verify this any time via the padlock in your browser's address bar.
Card payments
Payments are processed by Stripe using its hosted, embedded checkout. Card numbers, CVCs and expiry dates are submitted directly to Stripe — a PCI DSS Level 1 certified service provider — and never reach or get stored on our servers. We retain only the payment reference and order details needed for your receipt and support.
Accounts and access
Accounts are protected by hashed passwords or Google / Apple sign-in. Sessions use short-lived tokens, and database access rules restrict every record to its owner. Staff back-office access is limited to named roles.
Data we store
We store the details needed to deliver and support your orders: recipient number or email, operator or brand, amount, status, and receipt history. Redemption codes are shown only to the purchaser and recipient. We do not sell your data.
Report a security issue
If you believe you've found a vulnerability or notice suspicious activity on your account, contact us and we'll respond as quickly as we can. Please avoid sharing full card numbers or passwords in your message.
security@zoesend.comFrequently asked questions
Is the ZOE Connect website encrypted?
Does ZOE Connect store my card number?
What is PCI DSS Level 1?
How do you protect my account?
What should I do if I notice suspicious activity?
Is my recipient's phone number or email secure?
Is ZOE Connect SOC 2 or ISO 27001 compliant?
Shared responsibility: the controls above cover the ZOE Connect service and its hosting and payment providers. Keeping your password private, your device secure, and your recipient details accurate remains your responsibility.
