ServinYOU
  • Home
  • Pricing
  • FAQ

Compliance

Industry Standards & Regulatory Requirements We Meet

Quick Navigation

  • Compliance Overview
  • PCI DSS
  • GDPR
  • CCPA/CPRA
  • Accessibility (ADA)
  • Data Retention Laws
  • Food Business Laws
  • Audits & Certifications
  • Compliance Contact

1. Compliance Overview

ServinYOU operates in a highly regulated environment involving payments, customer data, and business operations. We maintain comprehensive compliance with applicable laws and industry standards across multiple jurisdictions.

Our Compliance Commitment
We proactively maintain compliance with all applicable regulations, conduct regular audits, update policies as laws change, and maintain transparency with our customers about how we handle their data.

Compliance Standards We Maintain

Standard Focus Area Status
PCI DSS Level 1 Payment Card Security ✓ Compliant
GDPR EU Data Protection ✓ Compliant
CCPA/CPRA California Privacy ✓ Compliant
SOC 2 Type II Security & Availability ✓ Compliant
ADA Accessibility Web Accessibility ✓ Compliant

2. PCI DSS (Payment Card Industry Data Security Standard)

What is PCI DSS?

PCI DSS is a set of security requirements established by major credit card companies (Visa, Mastercard, American Express, Discover) to protect payment card information from fraud and data breaches. It applies to any organization that accepts, processes, transmits, or stores payment card data.

Our PCI DSS Level 1 Status

We maintain PCI DSS Level 1 compliance, the highest validation level required for high-volume payment processors:

  • Annual third-party security assessment by qualified assessor
  • Quarterly network scans by approved scanning vendor
  • Compliance validation and audit reports
  • Proactive vulnerability management

PCI DSS Requirements We Meet

Secure Network Architecture

We maintain firewalls, network segmentation, and intrusion prevention systems. No direct public access to cardholder data environments.

Cardholder Data Protection

Strong encryption, secure deletion procedures, restricted access, and regular security testing protect payment card information.

Vulnerability & Patch Management

Regular security updates, vulnerability scanning, and immediate patching of discovered issues ensure systems stay secure.

Access Control & Authentication

Multi-factor authentication, role-based access control, and strong password policies limit unauthorized access.

Your PCI Compliance Responsibilities

While we handle payment processing securely, you also have responsibilities:

  • Never store full credit card numbers
  • Use the secure payment interface provided by ServinYOU
  • Don't transmit card data through unsecured channels
  • Maintain secure staff access controls
  • Train staff on payment security best practices

3. GDPR (General Data Protection Regulation)

What is GDPR?

GDPR is the European Union's comprehensive data protection regulation that applies to any organization processing personal data of EU residents. It requires organizations to:

  • Obtain explicit consent before processing personal data
  • Implement privacy by design
  • Protect personal data with strong security
  • Respect individuals' privacy rights (access, correction, deletion, portability)
  • Report data breaches within 72 hours

Our GDPR Compliance Measures

Data Processing Agreements

We provide Data Processing Agreements (DPA) that comply with GDPR Article 28 requirements for all business customers.

Individual Rights Support

We enable customers to fulfill GDPR subject rights requests (access, correction, deletion, portability) from their customers.

Standard Contractual Clauses

For data transfers outside the EU, we implement Standard Contractual Clauses (SCCs) as approved by the European Commission.

Breach Notification

We notify EU supervisory authorities and affected individuals within 72 hours of discovering a personal data breach.

EU Representative

For GDPR inquiries from EU residents, please contact: gdpr@pickngo.com

4. CCPA/CPRA (California Privacy Laws)

What is CCPA/CPRA?

The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant California residents specific rights over their personal information. The law applies to businesses that collect personal data from California residents if they meet certain thresholds.

Consumer Rights We Support

  • Right to Know: Consumers can request what personal information we collect and how it's used
  • Right to Delete: Consumers can request deletion of their personal information
  • Right to Opt-Out: Consumers can opt-out of personal information sales or sharing
  • Right to Correct: Consumers can request correction of inaccurate information
  • Right to Non-Discrimination: We don't discriminate for exercising privacy rights

Our CCPA/CPRA Compliance

  • Clear privacy notices explaining data collection practices
  • Easy opt-out mechanisms for marketing and data sharing
  • Tools to help you submit consumer rights requests
  • No sale of personal information to third parties
  • Reasonable response times (within 45 days) for requests

California Privacy Rights

California residents have specific rights regarding their information. See our Privacy Policy for details on how to exercise these rights.

5. Accessibility Compliance (ADA/WCAG)

Our Accessibility Commitment

ServinYOU is committed to making our platform accessible to individuals with disabilities. We aim to comply with:

  • WCAG 2.1 Level AA: Web Content Accessibility Guidelines
  • ADA: Americans with Disabilities Act
  • Section 508: Federal technology accessibility standards

Accessibility Features

Screen Reader Support

Our interface is compatible with screen readers like JAWS, NVDA, and VoiceOver for visually impaired users.

Keyboard Navigation

Full keyboard navigation without requiring a mouse, with clear focus indicators.

Resizable Text & Colors

Text can be resized without breaking layout, with sufficient color contrast ratios.

Semantic HTML

Proper heading structure, form labels, and semantic markup for assistive technologies.

Accessibility Support

If you experience accessibility barriers, please contact: accessibility@pickngo.com

6. Data Retention & Tax Compliance

Transaction Record Retention

We retain transaction records in accordance with applicable laws:

  • Tax Records: 7 years (IRS requirement and industry standard)
  • Payment Card Records: 7 years (PCI DSS requirement)
  • Customer Information: 2 years after account closure
  • Marketing Preferences: Until customer unsubscribes

Your Responsibilities

You remain responsible for:

  • Maintaining your own records as required by law
  • Tax compliance and reporting to IRS/state agencies
  • Downloading and storing reports for your records
  • Notifying us of legal retention requirements

Data Deletion Requests

After the required retention period, you can request data deletion. We will permanently delete data within 30 days while maintaining records needed for tax compliance.

7. Food Business Compliance

Important Disclaimer

⚠️ Your Responsibility: ServinYOU does not provide legal or compliance advice regarding food safety, health codes, or licensing requirements. You remain solely responsible for complying with all applicable food safety laws, health regulations, and business licensing requirements in your jurisdiction.

Your Compliance Obligations

As a food truck or restaurant operator, you must ensure compliance with:

  • Food Safety Laws: FDA Food Safety Modernization Act (FSMA), state food codes
  • Health Permits: Local health department requirements and inspections
  • Business Licensing: Federal, state, and local business licenses
  • Labor Laws: Minimum wage, overtime, employee classification
  • Tax Compliance: Sales tax, income tax, payroll taxes
  • Accessibility: ADA requirements for your physical location
  • Alcohol Licenses: If applicable, liquor licensing requirements

How ServinYOU Helps

While we don't provide legal compliance, our system helps you:

  • Maintain accurate sales records for tax reporting
  • Track inventory for compliance audits
  • Document payment transactions
  • Manage menu items and pricing
  • Generate reports for business records

Recommendation

We strongly recommend consulting with:

  • Local health department for food safety requirements
  • CPA or accountant for tax compliance
  • Employment attorney for labor law questions
  • Business attorney for licensing and contracts

8. Audits & Certifications

Annual Compliance Audits

  • PCI DSS assessment by qualified security assessors
  • SOC 2 Type II audit by independent auditors
  • Vulnerability assessments and penetration testing
  • GDPR/CCPA compliance reviews

Continuous Monitoring

  • Monthly security scanning and testing
  • Quarterly compliance audits
  • Real-time monitoring of systems and logs
  • Regular policy and procedure reviews

Audit Reports & Documentation

We maintain comprehensive audit reports and documentation of our compliance efforts. Enterprise customers can request copies of relevant compliance reports under appropriate confidentiality agreements.

Remediation & Improvement

When audits identify opportunities for improvement, we:

  • Develop remediation plans
  • Implement fixes and enhancements
  • Verify corrections through re-testing
  • Document all improvements

9. Compliance Questions & Requests

For compliance-related questions, audit documentation requests, or to discuss specific regulatory requirements:

Email: compliance@servinyou.com
Phone: [Your Phone Number]
Mailing Address: ServinYOU, Compliance Department, [Your Address]
Response Time: We will respond within 5 business days

Compliance Resource Center

We provide resources to help you maintain compliance:

  • Documentation and templates
  • Compliance guides and best practices
  • Links to relevant regulations and authorities
  • Training materials for your team

Your Compliance Responsibility

Important: While we maintain our systems in compliance with applicable laws, you remain responsible for:

  • Complying with all laws applicable to your business
  • Proper use of our system consistent with regulations
  • Protecting your login credentials and customer data
  • Notifying us of any compliance concerns
  • Consulting with legal counsel for your specific jurisdiction
Last Updated: September 2024
This Compliance page is updated regularly to reflect current regulatory requirements and our commitments. Laws change frequently, and we encourage you to stay informed about regulations affecting your business.
← Back to Home