
Google Sheet Extension
PDF to Pass
Image to Pass
Trust Center / AddToWallet.co
Review AddToWallet.co compliance posture, privacy practices, security controls, customer-facing documents, and data deletion request options.






Grouped controls with implementation status.
Production infrastructure is monitored to identify availability, reliability, and security concerns.
ActiveAutomatic backups support customer data recovery and service continuity.
ActiveProduction systems can only be remotely accessed by authorized employees with valid MFA.
ActiveRemote production access requires approved encrypted connections.
ActiveSensitive customer data is prohibited from being used or stored in non-production environments.
ActiveNetwork segmentation helps prevent unauthorized customer data access.
ActiveProduction network access requires unique credentials or authorized SSH keys.
ActiveSystems and applications require unique user authentication or authorized SSH keys.
ActiveA multi-location strategy supports recovery if a facility is unavailable.
ActiveFormal policies define requirements for vulnerability management and system monitoring.
ActiveSoftware delivery follows secure development practices throughout implementation and release.
ActiveSecrets are managed to reduce exposure of credentials, keys, and sensitive configuration.
ActiveApplication inputs are validated to protect product workflows and customer data.
ActiveBackground checks are performed for new employees.
ActiveEmployees complete security awareness training within thirty days of hire and at least annually.
ActiveContractors sign confidentiality agreements at engagement.
ActiveA formal inventory of production system assets is maintained.
ActiveEmployees sign confidentiality agreements during onboarding.
ActiveElectronic media containing confidential information is purged or destroyed according to best practices.
ActiveBC/DR plans are documented and tested at least annually.
ActiveThe incident response plan is tested at least annually.
ActiveAccess is based on job role or documented manager-approved requests.
ActiveBackup and recovery requirements for customer data are documented.
ActiveSecurity and privacy incident response policies are documented and communicated.
ActiveConfiguration procedures keep system configurations consistent.
ActiveManagement oversees control design and implementation responsibilities.
ActiveProduct and service descriptions are communicated to users.
ActiveSecurity policies are documented and reviewed at least annually.
ActiveUsers can report failures, incidents, concerns, and complaints.
ActiveSecurity control responsibilities are formally assigned.
ActiveData center access is reviewed at least annually.
ActiveA formal SDLC governs systems and technology changes.
ActiveCybersecurity insurance mitigates financial impact from disruptions.
ActiveBC/DR plans include communication plans for security continuity.
ActiveThe privacy policy communicates collection, obligations, rights, and contact points.
ActiveFormal retention and disposal procedures guide secure handling of data.
ActivePrivacy complaints are addressed, documented, tracked, and communicated.
ActiveThe privacy policy is available before or when information is collected.
ActiveThe privacy policy is reviewed when needed or when changes occur.
ActiveThe policy explains jurisdictions, rights, data categories, collection, sources, and disclosures.
ActiveDeletion requests are validated, flagged, and completed under applicable requirements.
ActiveBC/DR communication plans support security continuity if key personnel are unavailable.
ActiveThe documented BC/DR plan is tested annually.
ActivePII collection is limited to the minimum necessary for its purposes.
ActivePII is encrypted in transit.
ActiveInfrastructure, database, analytics, and product-experience vendors used to operate the service.
Cloud infrastructure and hosting.
Cloud infrastructure and platform services.
Cloud infrastructure and regional processing.
Database hosting and data storage.
Website analytics and usage measurement.
Product analytics and session experience insights.
Submit a request to delete personal data associated with AddToWallet.co.
Requests are validated before deletion to protect account security and avoid accidental loss.