Trust

Security at NicheMaps

How we protect your account and data. Security is a shared responsibility we take seriously.

Looking for policies, subprocessors, or a DPA / questionnaire request? Start at the Trust Center.

Encryption everywhere

Your connection to NicheMaps is encrypted in transit, and the data we store is encrypted at rest.

Least-privilege access

Access to systems and customer data is limited to what is required to operate the product. Secrets are kept out of application code.

Hardened hosting

We run on a major cloud platform with isolation between components and ongoing security updates.

Payment security

Card details are handled entirely by Stripe, a PCI-DSS Level 1 provider. We never see or store your full card number.

Minimal data collection

We collect only what's needed to run your account. We never sell your personal data.

Backups & resilience

Core data is backed up for durability, and the service is designed for high availability.

Reporting a vulnerability

We welcome responsible disclosure. If you believe you've found a security issue, please email security@nichemaps.io with details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure. We appreciate your help keeping the platform safe.

Data sources & compliance

Ad-creative data is sourced from public, regulator-mandated transparency centers (Google Ads Transparency Center, Meta Ad Library). App catalog and metric data come from public store listings. We link back to the original sources so any data point can be independently verified.