Security & Data Protection
Last updated: 25 August 2026
This page explains how NomaDrop LLC, operator of the Bagazin platform, protects personal data and payment information. It is written for customers, partners, and payment-service providers reviewing our security posture.
1. Payment security and PCI scope
- We never store card numbers. When online card payments are offered, card data is entered directly into the payment processor’s embedded, tokenized fields. Card numbers never touch Bagazin servers, and NomaDrop staff have no access to them.
- Processor-handled payments. Card transactions are processed end-to-end by our third-party PCI-DSS Level 1 payment processor. NomaDrop receives only a payment token and the transaction status — never the underlying card details.
- Strong Customer Authentication. Where required (including European and Moroccan cards), 3-D Secure / SCA is applied by the processor at confirmation time.
- Current payment methods. Bookings are currently settled in cash on site at participating partners; no card data is collected while online payments are disabled. Online card payments will be announced before they go live, and this page will be updated accordingly.
- Currency honesty. All prices are quoted and charged in Moroccan Dirham (MAD). No currency conversion is applied at checkout.
2. Transport and platform encryption
- The entire platform is served over HTTPS with TLS; HTTP requests are redirected to HTTPS and HTTP Strict Transport Security (HSTS) is enabled.
- Security headers — including Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and Referrer-Policy — are applied site-wide to limit cross-site scripting, clickjacking and referrer leakage.
- Data at rest is encrypted by our infrastructure providers.
3. Application and database security
- Row-Level Security (RLS) is enforced on every table in our Postgres database (Supabase), so users can only read and write the records they are entitled to.
- Privileged operations (payments, payouts, partner financial data) run through server-side functions with explicit permission checks, never through direct client access.
- Administrative access is restricted to named role-based accounts (support, finance, super-admin tiers) with least-privilege permissions.
- Financial tables enforce non-negative amount checks at the database level.
4. Account security
- Authentication is handled by Supabase Auth with one-time-password (OTP) and OAuth options; we do not store passwords in plain text.
- Native app sign-in uses PKCE. Session tokens are stored in the platform’s secure storage, not in web views accessible to third-party scripts.
- You can close your account and request deletion of your personal data at any time via support@bagazin.com.
5. Third-party providers
We rely on a small set of vetted providers acting on our instructions: Supabase (database, auth, storage), our payment processor (card tokenization and capture), Google Firebase (push notifications), and map/routing services for location features. Each receives only the data needed for its function. See our Privacy Policy for details.
6. Responsible disclosure
If you believe you have found a security vulnerability in Bagazin, please report it to support@bagazin.com with a description and reproduction steps. We investigate all credible reports and ask that you do not access or modify other users’ data while testing.
7. Contact
Security and data-protection questions: support@bagazin.com. Company details are on our Contact page.
Bagazin is operated by NomaDrop LLC, a limited liability company registered in Wyoming, USA. Registered office: 1309 Coffeen Avenue, STE 1200, Sheridan, Wyoming 82801, USA.