Security at NicheMaps
How we protect your account and data. Security is a shared responsibility we take seriously.
Looking for policies, subprocessors, or a DPA / questionnaire request? Start at the Trust Center.
Encryption everywhere
Your connection to NicheMaps is encrypted in transit, and the data we store is encrypted at rest.
Least-privilege access
Access to systems and customer data is limited to what is required to operate the product. Secrets are kept out of application code.
Hardened hosting
We run on a major cloud platform with isolation between components and ongoing security updates.
Payment security
Card details are handled entirely by Stripe, a PCI-DSS Level 1 provider. We never see or store your full card number.
Minimal data collection
We collect only what's needed to run your account. We never sell your personal data.
Backups & resilience
Core data is backed up for durability, and the service is designed for high availability.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you've found a security issue, please email security@nichemaps.io with details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure. We appreciate your help keeping the platform safe.
Data sources & compliance
Ad-creative data is sourced from public, regulator-mandated transparency centers (Google Ads Transparency Center, Meta Ad Library). App catalog and metric data come from public store listings. We link back to the original sources so any data point can be independently verified.