addToWallet.co
Workspaces
Pricing
API Docs
Tutorial Blog
Tools
Google Sheet Extension
PDF to Pass
Image to Pass
QR Code Generator
Barcode Generator
Integrations
© 2026 Hazelnut Ventures LLC. All Rights Reserved.
FAQsTrustContact Us

Resources

Privacy PolicyTerms of Service

Trust Center / AddToWallet.co

Security and privacy overview

Review AddToWallet.co compliance posture, privacy practices, security controls, customer-facing documents, and data deletion request options.

Compliance

Verified
EU-U.S. Data Privacy Framework badge
EU-U.S. Data Privacy Framework
Verified
Data Privacy Framework badge
UK Extension and Swiss-U.S. DPF
Verified
CSA STAR Level One badge
CSA STAR Level 1
Ready
GDPR compliant badge
GDPR compliant
Ready
CCPA compliant badge
CCPA compliant
Ready
WCAG 2.2 badge
WCAG 2.2 compliant
Active
TLS 1.2 badge
TLS 1.2/1.3 encryption
Active
AES-256 encryption badge
AES-256 encryption at rest

Controls

Grouped controls with implementation status.

45 active
Infrastructure Security9 controls
Infrastructure monitoring

Production infrastructure is monitored to identify availability, reliability, and security concerns.

Active
Automatic backups

Automatic backups support customer data recovery and service continuity.

Active
Remote access MFA enforced

Production systems can only be remotely accessed by authorized employees with valid MFA.

Active
Remote access encrypted enforced

Remote production access requires approved encrypted connections.

Active
Production data segmented

Sensitive customer data is prohibited from being used or stored in non-production environments.

Active
Network segmentation implemented

Network segmentation helps prevent unauthorized customer data access.

Active
Unique network authentication enforced

Production network access requires unique credentials or authorized SSH keys.

Active
Unique account authentication enforced

Systems and applications require unique user authentication or authorized SSH keys.

Active
Multi-availability zones established

A multi-location strategy supports recovery if a facility is unavailable.

Active
Product Security4 controls
Vulnerability and system monitoring procedures

Formal policies define requirements for vulnerability management and system monitoring.

Active
Secure software development practices

Software delivery follows secure development practices throughout implementation and release.

Active
Secrets management

Secrets are managed to reduce exposure of credentials, keys, and sensitive configuration.

Active
Input validation

Application inputs are validated to protect product workflows and customer data.

Active
Organizational Security6 controls
Employee background checks performed

Background checks are performed for new employees.

Active
Security awareness training implemented

Employees complete security awareness training within thirty days of hire and at least annually.

Active
Contractor confidentiality agreement acknowledged

Contractors sign confidentiality agreements at engagement.

Active
Production inventory maintained

A formal inventory of production system assets is maintained.

Active
Employee confidentiality agreement acknowledged

Employees sign confidentiality agreements during onboarding.

Active
Asset disposal procedures utilized

Electronic media containing confidential information is purged or destroyed according to best practices.

Active
Internal Security Procedures15 controls
Continuity and Disaster Recovery plans tested

BC/DR plans are documented and tested at least annually.

Active
Incident response plan tested

The incident response plan is tested at least annually.

Active
Access requests required

Access is based on job role or documented manager-approved requests.

Active
Backup processes established

Backup and recovery requirements for customer data are documented.

Active
Incident response policies established

Security and privacy incident response policies are documented and communicated.

Active
Configuration management system established

Configuration procedures keep system configurations consistent.

Active
Management roles and responsibilities defined

Management oversees control design and implementation responsibilities.

Active
Service description communicated

Product and service descriptions are communicated to users.

Active
Security policies established and reviewed

Security policies are documented and reviewed at least annually.

Active
Support system available

Users can report failures, incidents, concerns, and complaints.

Active
Roles and responsibilities specified

Security control responsibilities are formally assigned.

Active
Data center access reviewed

Data center access is reviewed at least annually.

Active
Development lifecycle established

A formal SDLC governs systems and technology changes.

Active
Cybersecurity insurance maintained

Cybersecurity insurance mitigates financial impact from disruptions.

Active
Continuity and Disaster Recovery plans established

BC/DR plans include communication plans for security continuity.

Active
Data and Privacy11 controls
Privacy policy established

The privacy policy communicates collection, obligations, rights, and contact points.

Active
Data retention procedures established

Formal retention and disposal procedures guide secure handling of data.

Active
Privacy compliant procedures established

Privacy complaints are addressed, documented, tracked, and communicated.

Active
Privacy policy available

The privacy policy is available before or when information is collected.

Active
Privacy policy reviewed

The privacy policy is reviewed when needed or when changes occur.

Active
Privacy policy maintained

The policy explains jurisdictions, rights, data categories, collection, sources, and disclosures.

Active
Data deletion requests handled

Deletion requests are validated, flagged, and completed under applicable requirements.

Active
Continuity and Disaster Recovery plans established

BC/DR communication plans support security continuity if key personnel are unavailable.

Active
Continuity and Disaster Recovery plans tested annually

The documented BC/DR plan is tested annually.

Active
Limit collection

PII collection is limited to the minimum necessary for its purposes.

Active
PII transmission controls for processor

PII is encrypted in transit.

Active

Subprocessor list

Infrastructure, database, analytics, and product-experience vendors used to operate the service.

6 listed›
AWS
US

Cloud infrastructure and hosting.

Azure
US

Cloud infrastructure and platform services.

GCP
EU

Cloud infrastructure and regional processing.

MongoDB
US, EU

Database hosting and data storage.

Google Analytics
Global

Website analytics and usage measurement.

Microsoft Clarity
Global

Product analytics and session experience insights.

Data deletion request

Submit a request to delete personal data associated with AddToWallet.co.

›

How requests are handled

Requests are validated before deletion to protect account security and avoid accidental loss.

  • ✓Deletion requests are reviewed against applicable law and customer obligations.
  • ✓Confirmed requests are flagged and processed through the designated privacy workflow.
  • ✓Only the minimum necessary personal information is collected for validation.
  • ✓PII transmitted through the service is encrypted in transit.

Request deletion

Do not include passwords, payment details, or unrelated sensitive information.