1. Card Data
In direct-payment configurations such as Zelle, Cash App, Venmo, or supported local payment apps, no card number, PIN, or CVV is entered into TapKio. Because no card data is captured at the kiosk, Restaurants may reduce card-data handling compared with traditional card-based kiosks.
PCI DSS scope is determined by the Restaurant's overall payment setup, not by TapKio alone. Restaurants accepting cards through other systems remain responsible for PCI compliance for those systems.
2. Transport Security
Connections between the kiosk, the staff confirmation dashboard, and TapKio services use industry-standard transport encryption (HTTPS / TLS).
3. Data at Rest
Credentials and other sensitive configuration data are stored using industry-standard encryption. Backups are encrypted in transit and at rest.
4. Access Controls
Staff accounts on the confirmation dashboard support per-staff PINs and role-based permissions (cashier, manager, owner). TapKio uses least-privilege internal access, multi-factor authentication for administrative tools, and access logging for production systems.
5. Sub-processors and Hosting
TapKio runs on reputable cloud infrastructure and uses a limited set of sub-processors for hosting, error monitoring, analytics, and messaging. We require contractual commitments from these providers around confidentiality and data protection.
6. Logging and Monitoring
We log access to production systems, monitor for anomalies, and review logs as part of routine operations and incident response.
7. Vulnerability Management
We track dependencies, apply security updates on a risk-prioritized schedule, and use automated scanning tools as part of our development process.
8. Incident Response and Notification
We maintain an incident response process. In the event of a security incident affecting personal information processed on behalf of a Restaurant, we will notify the Restaurant without undue delay so the Restaurant can meet its own notification obligations under applicable law.
9. Restaurant Responsibility
Restaurants are responsible for: keeping account credentials, PINs, and recovery codes confidential; promptly removing former employees from the dashboard; training staff on the confirmation workflow and on payment-fraud red flags; securing the physical kiosk hardware and its network; keeping operating systems and other payment systems patched; and maintaining backups of their own business records.
10. Reporting a Vulnerability
Please report suspected security issues to the email hello@tapkio.com. We ask researchers to test only against systems they own or have permission to test, to avoid privacy or service disruption, and to give us a reasonable opportunity to investigate and remediate before public disclosure. Do not include sensitive personal data in initial reports.