Security & Trust
Your security and privacy are our top priorities. Learn how we protect your data, payments, and personal information.
Payment Safety
All payments are processed securely through Stripe, a PCI-DSS Level 1 certified payment processor. We never store your full card details.
- Encrypted Transactions: All payment data is encrypted in transit using TLS 1.3
- Tokenized Storage: We only store tokenized payment methods, never raw card numbers
- Escrow Protection: Funds are held securely until job completion and customer confirmation
- Refund Policy: Booking deposits are refundable before mover acceptance or within 24 hours
Data Protection
We implement industry-standard security measures to protect your personal information.
- Encryption at Rest: All data stored in our database is encrypted
- Secure Authentication: Passwords are hashed using bcrypt with salt rounds
- HTTPS Only: All connections use HTTPS with valid SSL certificates
- Access Controls: Role-based access control ensures users can only access their own data
Abuse Prevention
We actively monitor and prevent abuse to maintain a safe platform for all users.
- Rate Limiting: API endpoints are rate-limited to prevent abuse and ensure fair usage
- Input Validation: All user input is validated and sanitized to prevent injection attacks
- Fraud Detection: We monitor for suspicious patterns and fraudulent activity
- Account Security: Failed login attempts are rate-limited and monitored
Monitoring & Logging
We continuously monitor our systems for security events and anomalies.
- Security Event Logging: All authentication attempts, payment events, and security-relevant actions are logged
- Anomaly Detection: We monitor for unusual patterns that may indicate security issues
- Privacy-Preserving: Logs are sanitized to remove sensitive information like passwords and payment details
Responsible Disclosure
If you discover a security vulnerability, we appreciate your help in disclosing it responsibly.
Please report security issues to:
security@mova-moving.com
We will acknowledge your report within 48 hours and work with you to resolve the issue. We ask that you:
- Do not access or modify data that does not belong to you
- Do not disrupt our services or impact other users
- Give us reasonable time to fix the issue before public disclosure
Questions about security? We're here to help.
Contact Us