CostLoop is a subscription and recurring cost tracker for small businesses and freelancers. This page summarises the security measures, infrastructure, and data practices in place. If you have additional questions, contact us at [email protected].
Infrastructure & Hosting
The CostLoop marketing website is deployed via Cloudflare Pages, one of the world's largest and most trusted CDN and security platforms. Cloudflare provides DDoS protection, Web Application Firewall (WAF), and automatic edge caching across 300+ global data centres.
All traffic to costloop.app and app.costloop.app is served exclusively over HTTPS with TLS 1.2/1.3. HTTP requests are automatically redirected to HTTPS. HTTP Strict Transport Security (HSTS) is enabled. You can verify our SSL configuration independently via SSL Labs.
CostLoop sets the following HTTP security headers on all responses: X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy (camera, microphone, geolocation, and payment all disabled), X-XSS-Protection, and Cross-Origin-Opener-Policy.
costloop.app has no malware, phishing, or unsafe content flags. Verify independently: Google Safe Browsing.
Data & Privacy Practices
CostLoop never connects to your bank account, requests banking credentials, or integrates with open banking APIs. Users add subscriptions manually. No sensitive financial data is stored on CostLoop servers.
Billing and payment processing is handled entirely by Stripe, Inc. - a PCI DSS Level 1 certified payment processor. CostLoop never sees, stores, or processes raw payment card numbers. Stripe's security documentation is available at stripe.com/docs/security.
User account data and subscription records are stored in Supabase, hosted within the European Union. Supabase is SOC 2 Type II compliant and encrypts data at rest and in transit. Passwords are hashed and never stored in plain text.
CostLoop does not sell user data to third parties, does not use advertising trackers, and does not build user profiles for marketing purposes. The only analytics tool used is Google Analytics with Consent Mode v2 - no data is collected without explicit user consent.
Compliance & Regulations
CostLoop is committed to global privacy compliance. The following regulations are addressed in our Privacy Policy:
Independent Verification
You can verify CostLoop's security status independently using the following tools - no account required:
Subprocessors
CostLoop uses a minimal set of third-party service providers to deliver the service. A full list including the purpose, data processed, and transfer mechanisms for each provider is available on our Subprocessors page.
Current subprocessors: Stripe (payments), Supabase (database & auth, EU-hosted), Resend (transactional email), Vercel (web hosting). All non-EU providers operate under Standard Contractual Clauses (SCCs).
Responsible Disclosure
If you discover a security vulnerability in CostLoop, please report it responsibly by emailing [email protected] with the subject line "Security Disclosure". We will acknowledge receipt within 2 business days and work to resolve confirmed issues promptly. We do not operate a bug bounty programme at this time.
Our security disclosure policy is also documented at /.well-known/security.txt.
Contact
For security-related questions, IT whitelisting requests, or enterprise security reviews, contact us at [email protected]. We respond within 1 business day.