Security

We take the protection of your account and your business data seriously. This page describes our approach at a high level.

Last updated: 29 September 2026

Account protection

  • Secure sign-in with server-side sessions.
  • Two-step verification with an authenticator app, and a fresh confirmation for sensitive actions such as changing where payments go or creating refunds.
  • Unusual sign-in activity and repeated failures are limited and recorded.

Your data

  • Connections to TummyMumma are encrypted in transit (HTTPS).
  • Each business’s data is kept separate from every other business.
  • Roles limit what staff members can see and do.
  • Important changes — for example to payment settings, refunds and disputes — are recorded in an audit trail.

Payments

  • TummyMumma never asks for or stores UPI PINs, card numbers, CVVs or banking passwords.
  • Where a regulated payment provider is used, payment details are entered on that provider’s own secure page and handled by the provider.
  • Payment confirmations are recorded with who or what confirmed them.

Our commitment

No system can be guaranteed to be completely secure, but we work to apply reasonable safeguards and keep improving them. We do not claim any security certification.

Reporting a security concern

If you believe you have found a security issue, please email admin@tummymumma.com with a description and steps to reproduce. Please do not access other people’s data, disrupt the service or publish details before we have had a chance to respond.