Security
You are trusting us with cash figures and your employees' salaries. Here is what we do about that.
Our approach
A pump's Maxify account holds the two things a business is most careful with: what the day took, and what each person is paid. We would rather state our posture plainly and let you judge it than publish a page of reassuring adjectives.
Where a claim on this page is specific, it is because we can back it. Where we cannot yet make a commitment, we have left it out rather than implied one.
Hosting and infrastructure
The application and its database run on managed cloud infrastructure, with the provider and region shown below.
- Provider
- Vercel
- Region
- Mumbai (ap-south-1)
Data in transit
All traffic to this website and to the application is served over HTTPS with TLS. There is no unencrypted route into the product.
Data at rest
Stored data and backups are encrypted at rest by the infrastructure the product runs on.
- Encryption at rest
- Encrypted at rest by the managed database provider
Access control
Inside your account, what someone can see and do follows their role: an attendant submits their own readings and cash, a manager reviews and approves, an owner sees the rollup. One pump's data is never visible to another business.
- Internal access
- Limited to authorised engineers on a need-to-know basis, for support and incident response
Backups
Backups are taken on the schedule shown below and are restorable. A ledger is only worth keeping if it survives a bad day.
- Backup schedule
- Automated daily backups with point-in-time restore
Payments
We never store card numbers. Subscription payments run through a payment gateway that holds those details under its own PCI obligations, and we hold only the record that a payment was made.
This website
The marketing site you are reading is deliberately inert. It runs no analytics, sets no advertising or tracking cookie, and loads no third-party script at runtime — the fonts are self-hosted at build time, so opening this page makes no request to Google.
The only things it stores on your device are a cookie remembering your language choice and a short-lived entry recording that you have already seen the opening animation. Both are described in the Privacy Policy.
If something goes wrong
No system is perfectly secure. If a breach affects your personal data we will notify you and the Data Protection Board of India as the DPDP Act 2023 requires, tell you what we know rather than waiting until we know everything, and say what we are doing about it.
- Breach notification
- Without undue delay, to affected users and to the Data Protection Board of India, as the DPDP Act 2023 requires
Getting your data out, and getting it deleted
Your data is exportable throughout your subscription. When you leave, you leave with it: there is a wind-down window to export, after which the data is deleted or irreversibly anonymised, except records we are legally required to retain.
Reporting a vulnerability
If you have found a security problem, tell us before you tell anyone else and we will work with you on it. Email is the right channel — please do not include exploit details in a WhatsApp message.