Secure 256-bit SSL encryption

Security at ZOE Connect

This page is maintained by ZOE Connect to answer common security and privacy questions about our service. It describes the controls that are active today — it is not an independent audit or certification of ZOE Connect.

Controls in place

256-bit SSL/TLS

Every page and payment is served over HTTPS with TLS 1.2+ and 256-bit encryption.

PCI DSS Level 1 payments

Card details go straight to Stripe, a PCI DSS Level 1 provider. We never see or store them.

Protected accounts

Passwords are hashed, sessions are token-based, and your data is isolated per account.

Verified delivery

Top-ups and gift cards are delivered through vetted licensed distribution partners.

Compliance & certifications

An independent SOC 2 examination of our security controls has been completed; the report is available to customers on request under NDA. ISO/IEC 27001 is listed as a program we are working toward — ZOE Connect is not ISO 27001 certified today.

SOC 2

Audit completed

An independent SOC 2 examination of our security controls has been completed. The report is available to customers on request under NDA.

PCI DSS Level 1

Via Stripe

Card data is handled entirely by Stripe, a PCI DSS Level 1 certified service provider. ZOE Connect never stores card numbers.

ISO/IEC 27001

Working toward

We are aligning our information security management practices with the ISO/IEC 27001 framework. ZOE Connect is not ISO 27001 certified today.

Encryption in transit

Every request to ZOE Connect is served over HTTPS. Our hosting provider terminates TLS 1.2+ using modern cipher suites with 256-bit symmetric encryption, and certificates are issued and renewed automatically. You can verify this any time via the padlock in your browser's address bar.

Card payments

Payments are processed by Stripe using its hosted, embedded checkout. Card numbers, CVCs and expiry dates are submitted directly to Stripe — a PCI DSS Level 1 certified service provider — and never reach or get stored on our servers. We retain only the payment reference and order details needed for your receipt and support.

Accounts and access

Accounts are protected by hashed passwords or Google / Apple sign-in. Sessions use short-lived tokens, and database access rules restrict every record to its owner. Staff back-office access is limited to named roles.

Data we store

We store the details needed to deliver and support your orders: recipient number or email, operator or brand, amount, status, and receipt history. Redemption codes are shown only to the purchaser and recipient. We do not sell your data.

Report a security issue

If you believe you've found a vulnerability or notice suspicious activity on your account, contact us and we'll respond as quickly as we can. Please avoid sharing full card numbers or passwords in your message.

security@zoesend.com
FAQ

Frequently asked questions

Is the ZOE Connect website encrypted?
Yes. Every request is served over HTTPS with TLS 1.2+ and modern 256-bit cipher suites. You can verify this by the padlock icon in your browser's address bar.
Does ZOE Connect store my card number?
No. Card numbers, CVCs, and expiry dates are submitted directly to Stripe through its hosted, embedded checkout. Stripe is PCI DSS Level 1 certified and handles all card data. We retain only the payment reference and order details.
What is PCI DSS Level 1?
PCI DSS (Payment Card Industry Data Security Standard) Level 1 is the highest level of certification for payment processors. It means Stripe undergoes annual third-party security audits and meets strict requirements for protecting cardholder data.
How do you protect my account?
Accounts are protected by hashed passwords or Google/Apple sign-in. Sessions use short-lived tokens, and database access rules restrict every record to its owner. We also recommend using a strong, unique password and keeping your device secure.
What should I do if I notice suspicious activity?
If you believe your account has been compromised or you notice suspicious activity, change your password immediately and contact us at security@zoesend.com. Please avoid sharing full card numbers or passwords in your message.
Is my recipient's phone number or email secure?
Yes. Recipient information is transmitted over encrypted connections and stored only as long as needed to deliver and support your order. We do not sell or share recipient data for marketing purposes.
Is ZOE Connect SOC 2 or ISO 27001 compliant?
An independent SOC 2 examination of our security controls has been completed, and the report is available to customers on request under NDA. ISO/IEC 27001 is a program we are actively working toward: we are not ISO 27001 certified today. Card payments are handled by Stripe, a PCI DSS Level 1 certified provider.

Shared responsibility: the controls above cover the ZOE Connect service and its hosting and payment providers. Keeping your password private, your device secure, and your recipient details accurate remains your responsibility.