Trust & Security
This page is maintained by Journey Stack (Wander Services Pte. Ltd.) to answer common security and privacy questions about our platform. It describes practices and controls currently in place. It is editable project content, not an independent certification or third-party audit attestation.
Platform & Hosting
Journey Stack runs on hardened, managed cloud infrastructure. Application data is stored in a managed Postgres database with Row Level Security enabled on all customer-facing tables. Backend logic that handles sensitive operations runs in isolated serverless functions using least-privilege service credentials.
All traffic to journeystack.co and our APIs is served over HTTPS (TLS) and HSTS is enforced. Data is encrypted in transit and at rest using industry-standard mechanisms provided by our infrastructure provider.
Access & Authentication
Administrative access to production systems is limited to authorised Journey Stack personnel and protected by multi-factor authentication. Database credentials and API keys are stored as platform-managed secrets and are not exposed to the client.
Public forms (contact, lead capture, calling beta signup) are protected by validation rules enforced both client-side and at the database layer (length limits, field shape, and Row Level Security policies).
Data Collection & Use
We collect only the information needed to deliver our services: account and contact details you submit through our forms, basic device and connectivity metadata required to provision eSIMs, and standard web analytics. We do not sell personal data.
A full description of categories collected, purposes, lawful bases, and your rights is available in our Privacy Policy.
Subprocessors & Integrations
Journey Stack relies on vetted infrastructure and communication providers (cloud hosting, managed database, transactional email, analytics, and telco/eSIM partners). We share only the minimum personal data required for each provider to perform its function under contract.
For an up-to-date list of subprocessors or to request a DPA, contact us at hello@journeystack.co.
Retention & Deletion
Personal data is retained only for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. You can request deletion of your personal data at any time by contacting us.
Privacy Requests
To exercise rights under applicable data-protection laws (access, correction, deletion, portability, objection), email privacy@journeystack.co. We respond within the timeframes required by applicable law.
Security & Incident Contact
To report a suspected vulnerability or security incident, email security@journeystack.co. Please include enough detail to reproduce the issue. We acknowledge legitimate reports and work to remediate confirmed issues promptly.
Shared Responsibility
Security is a shared responsibility. Journey Stack secures the platform, infrastructure, and application controls described above. Partners and customers are responsible for safeguarding their own account credentials, keeping API keys confidential, and configuring their own integrations and end-user-facing surfaces appropriately.
Compliance
We design our practices to align with GDPR, applicable Singapore PDPA requirements, and industry expectations for telecom and eSIM providers. This page does not claim certification under any specific standard; where partners require formal documentation (DPA, security questionnaire, subprocessor list), contact hello@journeystack.co.
This page is maintained by Journey Stack and reflects current practices at the time of publication. It is not an independent attestation or certification.