Security & Data Protection

Last updated: 25 August 2026

This page explains how NomaDrop LLC, operator of the Bagazin platform, protects personal data and payment information. It is written for customers, partners, and payment-service providers reviewing our security posture.

1. Payment security and PCI scope

2. Transport and platform encryption

3. Application and database security

4. Account security

5. Third-party providers

We rely on a small set of vetted providers acting on our instructions: Supabase (database, auth, storage), our payment processor (card tokenization and capture), Google Firebase (push notifications), and map/routing services for location features. Each receives only the data needed for its function. See our Privacy Policy for details.

6. Responsible disclosure

If you believe you have found a security vulnerability in Bagazin, please report it to support@bagazin.com with a description and reproduction steps. We investigate all credible reports and ask that you do not access or modify other users’ data while testing.

7. Contact

Security and data-protection questions: support@bagazin.com. Company details are on our Contact page.