Information Security Policy
Plus 2 Ventures LLC | SnapAttract
Effective Date: September 29, 2026
1. Purpose
Plus 2 Ventures LLC ("we," "us," or "our") operates the SnapAttract platform ("Service"). This Information Security Policy describes how we protect the confidentiality, integrity, and availability of the Service and the data entrusted to us, including account information, prospect data, and communications records.
2. Scope
This policy applies to all users of the Service, all data processed by the Service, and the third-party providers we rely on to deliver it. It covers the SnapAttract web application, its supporting infrastructure, and administrative access to production systems.
3. Data Protection
- Encryption in transit: All traffic between users and the Service is encrypted using TLS.
- Encryption at rest: Stored data, including databases and uploaded files, is encrypted by our infrastructure provider while at rest.
- Sensitive credentials: API keys and integration credentials (e.g., messaging and payment providers) are stored as encrypted server-side secrets and are never exposed to browsers or client-side code.
- Payment data: We never store credit card numbers. All payment information is handled by our payment processor, Stripe, in its PCI DSS-compliant environment.
4. Access Control
- Access to production data is restricted to authorized personnel on a least-privilege basis.
- Each user's workspace data is isolated, and users can only read and modify the prospect records, campaigns, and communications belonging to their own account.
- Administrative actions are limited to designated administrators and are reviewed on a regular basis.
- Passwords are never stored in plain text; authentication is managed by the platform's identity provider.
5. Infrastructure & Third-Party Providers
The Service is built on managed, enterprise-grade infrastructure. We partner only with reputable providers and share the minimum data necessary for each to perform its function:
- Base44 — Application infrastructure, database hosting, and authentication
- Twilio — SMS and voice message delivery
- Mailgun — Outbound email delivery
- Stripe — Payment processing and billing
6. Monitoring & Logging
We maintain logs of application activity, authentication events, and administrative actions to detect unauthorized access and support incident investigation. Logs are retained only as long as operationally necessary.
7. Incident Response
- Suspected security incidents are investigated promptly upon discovery.
- Where an incident affects user data, we will notify affected users and, where legally required, the appropriate authorities without undue delay.
- Root-cause analysis is performed after each incident, and corrective measures are implemented to reduce the risk of recurrence.
8. User Responsibilities
- Keep your account credentials confidential and do not share them with others.
- Ensure prospects' contact information is collected and used in compliance with applicable law and our Terms of Service.
- Notify us promptly if you suspect unauthorized access to your account.
9. Availability & Backup
We rely on managed infrastructure with built-in resilience and regular automated backups. While we target high availability, we do not guarantee uninterrupted service and recommend that users maintain their own copies of critical data.
10. Policy Review
This policy is reviewed at least annually and updated as our systems, providers, or legal obligations change. Material changes will be announced within the Service.
11. Contact Us
If you have questions about this Information Security Policy, or wish to report a suspected security issue, please contact:
Plus 2 Ventures LLC
Application: SnapAttract
Contact via the SnapAttract support channels.
© 2026 Plus 2 Ventures LLC. All rights reserved.