Compliance

    Our commitment to legal and regulatory compliance

    At PostcardMe, we're committed to operating in accordance with all applicable laws and regulations. This page outlines our compliance framework and the measures we take to protect our users.

    Data Privacy Compliance

    We recognize the importance of protecting personal data and comply with applicable data protection laws, including:

    General Data Protection Regulation (GDPR)

    For our European users, we comply with the GDPR by:

    • Processing personal data lawfully, fairly, and transparently
    • Collecting data for specified, explicit, and legitimate purposes
    • Limiting data collection to what's necessary
    • Ensuring data accuracy and keeping it up to date
    • Storing data only as long as necessary
    • Processing data securely
    • Being accountable and demonstrating compliance

    California Consumer Privacy Act (CCPA)

    For California residents, we comply with the CCPA by:

    • Providing notice about the personal information we collect
    • Honoring rights to access and delete personal information
    • Offering an opt-out from the sale of personal information
    • Not discriminating against consumers who exercise their rights

    Data Processing Agreements

    We maintain Data Processing Agreements with all third-party service providers who process personal data on our behalf, ensuring they maintain appropriate security and privacy standards.

    International Data Transfers

    When transferring data across borders, we implement appropriate safeguards such as Standard Contractual Clauses to protect personal information.

    Compliance Certifications

    🔒

    SOC 2 Type II

    Certified for security, availability, and confidentiality

    💳

    PCI DSS Level 1

    Highest level of payment security compliance

    🇪🇺

    GDPR Compliant

    Fully compliant with EU data protection law

    Compliance Reports and Documentation

    The following compliance documents are available upon request to verified customers and partners:

    • SOC 2 Type II Report
    • PCI DSS Attestation of Compliance
    • GDPR Data Processing Impact Assessment
    • Information Security Policy
    • Business Continuity Plan
    • Vulnerability Management Program

    To request access to compliance documentation, please contact our compliance team at compliance@postcardme.com.

    Report a Compliance Concern

    If you have concerns about our compliance with any regulations or standards, please contact us:

    Compliance Department
    PostcardMe, Inc.
    123 Main Street, Suite 456
    San Francisco, CA 94105

    Email: compliance@postcardme.com
    Phone: (555) 123-4567