Security is an ongoing responsibility
Security is not a one-time feature. It is an ongoing process of reducing risk, limiting access, monitoring the platform, improving safeguards, and responding responsibly when issues are discovered.
This page provides a practical overview of current security practices. It is not a guarantee that the Services are immune from every threat, and it does not disclose sensitive internal security details.
Secure connections and hosting
- GetBloomDirect is delivered over encrypted HTTPS connections.
- The application is hosted using established cloud infrastructure.
- Production data and services are separated from local development workflows.
- Infrastructure providers maintain their own physical and platform safeguards.
Account and authentication safeguards
- Passwords are stored using one-way password hashing rather than plain text.
- Session-based authentication is used to control access to protected areas.
- Email verification helps confirm ownership of newly registered email addresses.
- Authorization checks are applied to sensitive account, order, admin, and API actions.
- Suspended or ineligible accounts may be blocked from protected features.
Data access and storage
- Access is limited according to the needs of the platform and the user’s role.
- Shop-uploaded files are stored using cloud storage controls and private access where appropriate.
- Sensitive credentials and secrets are kept outside the public source code and client application.
- Order and account actions use server-side validation and authorization.
- We work to collect and retain only information reasonably needed to operate the Services.
Subscription payment security
Bloom Pro subscription payments are processed by Stripe. GetBloomDirect does not store full payment-card numbers in its application database. Stripe maintains its own security and compliance program for payment information processed through its services.
Florist-to-florist order payments are arranged directly between the participating shops using the payment methods they select. Users should independently protect those accounts and verify payment details.
Email, files, and integrations
- Transactional emails are delivered through a specialized email provider.
- Verification codes and similar credentials are time-limited where supported.
- POS API access requires a valid API key and eligible account.
- Webhook payloads may be signed so receiving systems can verify authenticity.
- API keys, webhook secrets, and connected-system credentials must be treated as confidential.
Operational safeguards
Our security work may include:
- Reviewing dependencies and platform changes
- Applying validation and least-privilege access patterns
- Investigating suspicious activity and reported vulnerabilities
- Restricting, suspending, or rotating access when risk is identified
- Improving logging, recovery, monitoring, and incident-response procedures as the platform grows
Your role in security
Every user helps protect the network. You should:
- Use a strong, unique password for GetBloomDirect
- Protect access to the email account connected to your shop
- Never share passwords, API keys, verification codes, or webhook secrets
- Remove access promptly when a staff member no longer needs it
- Verify unusual payment or order requests through a trusted channel
- Keep browsers, devices, POS systems, and connected software updated
- Report suspected unauthorized access or security concerns promptly
Responsible disclosure
We welcome good-faith reports that help us protect florists and the platform. Send suspected security vulnerabilities to getbloomdirect@gmail.com with the subject “Security Report.”
When researching or reporting an issue, please:
- Avoid accessing, modifying, downloading, or deleting data that is not yours
- Avoid disrupting the Services or degrading availability
- Do not use social engineering, phishing, physical attacks, or denial-of-service testing
- Provide enough detail for us to understand and reproduce the issue
- Give us a reasonable opportunity to investigate and address the issue before public disclosure
GetBloomDirect does not currently operate a paid bug-bounty program. A report does not create a right to payment or other compensation.
Security incidents
If we confirm a security incident affecting information, we will investigate, take reasonable steps to contain and remediate it, and provide notices when required by applicable law.
Questions or concerns
For general questions, use the GetBloomDirect contact page. For a suspected vulnerability or unauthorized account access, email getbloomdirect@gmail.com.