Security at PlanYour.Date
Security practices
- PlanYour.Date uses HTTPS for data in transit.
- Payments are handled by Stripe; PlanYour.Date does not store full payment-card numbers.
- Uploaded images are restricted to supported image formats, checked against their file content, and safely re-encoded before storage.
- Private invitation pages are excluded from the sitemap and marked not to be indexed by search engines.
- Invitation link previews use generic product metadata and do not expose the recipient name or invitation text.
- Rate limits and abuse controls protect sensitive public and account endpoints.
Report a vulnerability
Email support@planyour.date with the affected URL, clear reproduction steps, and the potential impact. Do not access, alter, retain, or disclose another person’s data while testing.
PlanYour.Date does not currently promise a public bug bounty or a fixed reward. Good-faith reports are reviewed through the official support channel.
Report an abusive invitation
Send the invitation URL or hash to support@planyour.date. Do not include passwords or payment-card details.