1.Protected Connections
SEZA production services are intended to use HTTPS/TLS for data moving between supported devices, browsers, payment services, and SEZA infrastructure. Merchants should use supported software, trusted networks, and current operating-system security updates.
2.Authentication and Access Control
SEZA uses account authentication, store-scoped authorization, employee roles, manager approvals, and separate platform-admin access. Merchants are responsible for protecting passwords and PINs, removing former employees, and assigning only the permissions each person needs.
3.Payment Information
SEZA subscription card details are entered into Stripe-hosted payment experiences. SEZA is designed to receive tokens, identifiers, and payment status instead of full subscription card numbers. Merchant card acceptance depends on the connected payment provider and supported hardware.
4.Audit and Operational Records
The Service includes audit-oriented records for sensitive workflows such as refunds, voids, cash movements, permission changes, device changes, and administrative actions. Coverage depends on the feature, configuration, and successful delivery of the event.
5.Availability and Recovery
SEZA uses managed service providers and application safeguards intended to reduce data-loss and outage risk. No internet service or software platform is completely secure or continuously available, and merchants should retain appropriate business records and contingency procedures.
6.Incident Response
SEZA investigates credible security reports, works to contain confirmed incidents, restores safe operation, and provides notices when required by applicable law or contract. The timing and content of any notice depend on the facts available during the investigation.
7.Report a Security Issue
Send suspected vulnerabilities to security@sezapos.com. Do not disrupt live stores, use social engineering, access unrelated data, or publicly disclose sensitive details before SEZA has a reasonable opportunity to investigate.
