Built to earn your finance team's approval.
This page is maintained by IncentivPay to answer common security and privacy questions about the platform. It describes current, enabled controls and is not an independent certification.

What we control, what you control.
IncentivPay operates the platform: authentication, encryption in transit and at rest, database security, RLS policies, and the incentive engine.
Merchants control: campaign configuration, staff access, promotional copy, and receipts uploaded through their own POS or Shopify connection. Customers control: their account, consent preferences, and wallet activity.
- TLS everywhere; database encryption at rest
- Least-privilege secrets, rotated regularly
- No PHI stored — healthcare integrations use appointment confirmation only
Frequently asked
Are you SOC 2 certified?+
IncentivPay is not currently SOC 2 certified. Enterprise merchants with certification requirements can reach out at sales@incentivpay.com to discuss the roadmap.
Are you GDPR / CCPA compliant?+
We honor deletion and data-access requests via support@incentivpay.com. Customers can also self-serve consent controls in their account settings.
Where can I report a security issue?+
Email security@incentivpay.com. We respond within one business day.
Talk to us about your security review.
Enterprise buyers get a security questionnaire template and direct engineering access.