Security
PointBagel reads your transactions to tell you which card to use and what your points are worth. Here is exactly how we protect that data, and what we never touch.
Read-only by design
We connect to your cards through Plaid, the same bank-linking network used by apps like Venmo and Robinhood. Plaid is SOC 2 Type II certified, and it handles the bank login itself, so your credentials never touch PointBagel.
- Read-only access. We can read transactions to find the best card for each purchase. We cannot move money.
- One product. We request a single Plaid product - transactions - and nothing else.
- Credit cards only. We only show credit-type accounts in the connect screen. Checking, savings, and investment accounts are never selectable.
- No balances stored. We do not pull or store your account balances, available credit, credit limits, or statement balances.
Want the full field-by-field inventory of what we collect and discard? Read our Privacy Policy.
How your data is protected
- Encrypted at rest
- Plaid access tokens and other sensitive values are encrypted at rest with AES-256-GCM.
- Encrypted in transit
- All data moving between you, us, and our providers travels over TLS 1.2 or higher.
- Password hashing
- Passwords are hashed with bcrypt at 12 rounds. We never store them in plain text.
- Two-factor authentication
- Optional authenticator-app 2FA, with single-use backup codes stored hashed, never in plaintext.
- Rate limits that fail closed
- Limits on sign-in and admin endpoints fail closed, blocking abuse instead of letting it through.
- Signature-verified webhooks
- Every incoming webhook is signature-verified before we act on it, so spoofed events are rejected.
- Least-privilege admin access
- Staff access follows a least-privilege role model, and every admin action is written to an audit log.
- Scrubbed error monitoring
- Error reports are stripped of personal data, access tokens, and auth headers before they leave our systems.
No system is perfectly secure, so we design assuming every layer will eventually be tested.
What we never see
- Your online banking username or password. Plaid handles the login itself, so we never see it.
- Full account or card numbers, CVV codes, or expiration dates.
- Routing numbers or other ACH identifiers.
- Your Social Security Number or identity documents.
And we never sell, rent, or trade your personal information. Your transactions, point balances, and card portfolio are never shared with card issuers, loyalty programs, or advertisers.
You stay in control
- Export everything
- Download a complete, machine-readable copy of your account data anytime: cards, point balances, Trip Plans, settings, and more.
- Delete your account
- One action removes your account and everything tied to it within 60 seconds.
- Disconnect a bank
- Disconnect any bank connection whenever you want. We permanently delete its transaction-level detail within 60 seconds, while your card-year value summaries stay visible.
- Revoke at the source
- Review or revoke our access at my.plaid.com. Under CFPB Section 1033 your authorization runs up to 12 months, then we re-ask.
Manage access at my.plaid.com. And if a breach ever affects your data, we will notify you without undue delay and no later than 30 days after we discover it.
Questions about security?
Email [email protected] and a human will answer. For the full detail, read our Privacy Policy and Data Retention Policy.
