Doloyal
Security

Security is the product

Last updated: July 20, 2026

This is a summary of our security policy. For the full legal agreement, please email hello@doloyal.com.

Encryption

All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Customer payment details are handled by PCI-DSS-compliant processors (Stripe & Razorpay) — we never store raw card numbers.

Access & authentication

  • Role-based access control across staff, branches, and plans
  • Optional multi-factor authentication on every account
  • Scoped API keys with rotation and instant revocation
  • Session management and activity logs you can review

Data protection practices

  • Customer data remains your property — never sold, never used for ad targeting
  • The AI retention engine operates only on your business data
  • Automated backups with verified restore processes
  • Right to export or delete your data at any time

Monitoring & incidents

We monitor infrastructure 24×7 with intrusion detection and anomaly alerts. In the unlikely event of a data incident, affected customers are notified within 72 hours, with the details we know and the steps we're taking.

Responsible disclosure

Found a vulnerability? Report it to hello@doloyal.com. We investigate every report, fix issues in priority order, and welcome the security community's help in keeping local businesses safe.