Security
Last updated: October 1, 2026
Report a vulnerability
Email hello@hotlineugc.com with "Security" in the subject line. Include:
- The page, feature or API endpoint affected
- The steps to reproduce it
- What an attacker could do with it
- How to reach you for follow-up questions
We acknowledge every report within 2 business days, send an update within 7 days, and tell you when the issue is fixed.
Rules for testing
Research done in good faith under these rules is authorised, and we will not pursue it.
- Test only with accounts and workspaces you own or have permission to use.
- Do not access, change or delete anyone else's data. If you reach personal data, stop, and tell us what you saw.
- No denial of service, spam, social engineering of our staff or users, or physical attacks.
- Give us reasonable time to fix the issue before you share it publicly.
Out of scope
- Output from automated scanners without a demonstrated impact
- Missing security headers or best practices without an exploit
- Rate limits on endpoints that hold no sensitive data or actions
- Vulnerabilities in the services we use, such as Stripe, Shopify, Meta or Clerk. Please report those to the service directly.
How we protect data
- All traffic uses HTTPS, with HSTS enforced.
- Access tokens for connected Meta and Shopify accounts are encrypted with AES-256-GCM before they are stored, and API keys are stored only as hashes.
- Card and bank details are entered with Stripe and never reach Hotline.
- Every workspace's data is kept separate, and roles decide what each member and creator can see.
- Errors and analytics are scrubbed of personal data and credentials before they leave the platform.
Security incidents
If an incident affects your data, we tell you without undue delay, with what happened, what data was involved and what we have done about it. Our Privacy Policy explains how we handle personal data.