CostLoop is a subscription and recurring cost tracker for small businesses and freelancers. This page summarises the security measures, infrastructure, and data practices in place. If you have additional questions, contact us at [email protected].

Infrastructure & Hosting

🟠
Hosted on Cloudflare Pages

The CostLoop marketing website is deployed via Cloudflare Pages, one of the world's largest and most trusted CDN and security platforms. Cloudflare provides DDoS protection, Web Application Firewall (WAF), and automatic edge caching across 300+ global data centres.

🔒
SSL/TLS Encrypted (HTTPS enforced)

All traffic to costloop.app and app.costloop.app is served exclusively over HTTPS with TLS 1.2/1.3. HTTP requests are automatically redirected to HTTPS. HTTP Strict Transport Security (HSTS) is enabled. You can verify our SSL configuration independently via SSL Labs.

🛡️
Security Headers

CostLoop sets the following HTTP security headers on all responses: X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy (camera, microphone, geolocation, and payment all disabled), X-XSS-Protection, and Cross-Origin-Opener-Policy.

Clean Malware & Safe Browsing Status

costloop.app has no malware, phishing, or unsafe content flags. Verify independently: Google Safe Browsing.

Data & Privacy Practices

🏦
No Bank Connections or Financial Credentials

CostLoop never connects to your bank account, requests banking credentials, or integrates with open banking APIs. Users add subscriptions manually. No sensitive financial data is stored on CostLoop servers.

💳
Payment Card Data Handled by Stripe Only

Billing and payment processing is handled entirely by Stripe, Inc. - a PCI DSS Level 1 certified payment processor. CostLoop never sees, stores, or processes raw payment card numbers. Stripe's security documentation is available at stripe.com/docs/security.

🗄️
Database & Authentication via Supabase (EU)

User account data and subscription records are stored in Supabase, hosted within the European Union. Supabase is SOC 2 Type II compliant and encrypts data at rest and in transit. Passwords are hashed and never stored in plain text.

📧
No Marketing Tracking or Data Selling

CostLoop does not sell user data to third parties, does not use advertising trackers, and does not build user profiles for marketing purposes. The only analytics tool used is Google Analytics with Consent Mode v2 - no data is collected without explicit user consent.

Compliance & Regulations

CostLoop is committed to global privacy compliance. The following regulations are addressed in our Privacy Policy:

Region Regulation Status
European UnionGDPR✓ Compliant
United KingdomUK GDPR✓ Compliant
SwitzerlandFADP✓ Compliant
ChinaPIPL✓ Compliant
JapanAPPI✓ Compliant
South KoreaPIPA✓ Compliant
Thailand / SingaporePDPA✓ Compliant
IndiaDPDP✓ Compliant

Independent Verification

You can verify CostLoop's security status independently using the following tools - no account required:

🔐 SSL Labs Test Check our TLS/SSL certificate grade Run test → 🛡️ Google Safe Browsing Verify no malware or phishing flags Check status → 📋 Security Headers Inspect our HTTP security headers Inspect headers → 🔍 Sucuri SiteCheck Independent malware scan Run scan →

Subprocessors

CostLoop uses a minimal set of third-party service providers to deliver the service. A full list including the purpose, data processed, and transfer mechanisms for each provider is available on our Subprocessors page.

Current subprocessors: Stripe (payments), Supabase (database & auth, EU-hosted), Resend (transactional email), Vercel (web hosting). All non-EU providers operate under Standard Contractual Clauses (SCCs).

Responsible Disclosure

If you discover a security vulnerability in CostLoop, please report it responsibly by emailing [email protected] with the subject line "Security Disclosure". We will acknowledge receipt within 2 business days and work to resolve confirmed issues promptly. We do not operate a bug bounty programme at this time.

Our security disclosure policy is also documented at /.well-known/security.txt.

Contact

For security-related questions, IT whitelisting requests, or enterprise security reviews, contact us at [email protected]. We respond within 1 business day.