1. Compliance Overview
ServinYOU operates in a highly regulated environment involving payments, customer data, and business operations. We maintain comprehensive compliance with applicable laws and industry standards across multiple jurisdictions.
Our Compliance Commitment
We proactively maintain compliance with all applicable regulations, conduct regular audits, update policies as laws change, and maintain transparency with our customers about how we handle their data.
Compliance Standards We Maintain
| Standard |
Focus Area |
Status |
| PCI DSS Level 1 |
Payment Card Security |
✓ Compliant |
| GDPR |
EU Data Protection |
✓ Compliant |
| CCPA/CPRA |
California Privacy |
✓ Compliant |
| SOC 2 Type II |
Security & Availability |
✓ Compliant |
| ADA Accessibility |
Web Accessibility |
✓ Compliant |
2. PCI DSS (Payment Card Industry Data Security Standard)
What is PCI DSS?
PCI DSS is a set of security requirements established by major credit card companies (Visa, Mastercard, American Express, Discover) to protect payment card information from fraud and data breaches. It applies to any organization that accepts, processes, transmits, or stores payment card data.
Our PCI DSS Level 1 Status
We maintain PCI DSS Level 1 compliance, the highest validation level required for high-volume payment processors:
- Annual third-party security assessment by qualified assessor
- Quarterly network scans by approved scanning vendor
- Compliance validation and audit reports
- Proactive vulnerability management
PCI DSS Requirements We Meet
Secure Network Architecture
We maintain firewalls, network segmentation, and intrusion prevention systems. No direct public access to cardholder data environments.
Cardholder Data Protection
Strong encryption, secure deletion procedures, restricted access, and regular security testing protect payment card information.
Vulnerability & Patch Management
Regular security updates, vulnerability scanning, and immediate patching of discovered issues ensure systems stay secure.
Access Control & Authentication
Multi-factor authentication, role-based access control, and strong password policies limit unauthorized access.
Your PCI Compliance Responsibilities
While we handle payment processing securely, you also have responsibilities:
- Never store full credit card numbers
- Use the secure payment interface provided by ServinYOU
- Don't transmit card data through unsecured channels
- Maintain secure staff access controls
- Train staff on payment security best practices
3. GDPR (General Data Protection Regulation)
What is GDPR?
GDPR is the European Union's comprehensive data protection regulation that applies to any organization processing personal data of EU residents. It requires organizations to:
- Obtain explicit consent before processing personal data
- Implement privacy by design
- Protect personal data with strong security
- Respect individuals' privacy rights (access, correction, deletion, portability)
- Report data breaches within 72 hours
Our GDPR Compliance Measures
Data Processing Agreements
We provide Data Processing Agreements (DPA) that comply with GDPR Article 28 requirements for all business customers.
Individual Rights Support
We enable customers to fulfill GDPR subject rights requests (access, correction, deletion, portability) from their customers.
Standard Contractual Clauses
For data transfers outside the EU, we implement Standard Contractual Clauses (SCCs) as approved by the European Commission.
Breach Notification
We notify EU supervisory authorities and affected individuals within 72 hours of discovering a personal data breach.
EU Representative
For GDPR inquiries from EU residents, please contact: gdpr@pickngo.com
4. CCPA/CPRA (California Privacy Laws)
What is CCPA/CPRA?
The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), grant California residents specific rights over their personal information. The law applies to businesses that collect personal data from California residents if they meet certain thresholds.
Consumer Rights We Support
- Right to Know: Consumers can request what personal information we collect and how it's used
- Right to Delete: Consumers can request deletion of their personal information
- Right to Opt-Out: Consumers can opt-out of personal information sales or sharing
- Right to Correct: Consumers can request correction of inaccurate information
- Right to Non-Discrimination: We don't discriminate for exercising privacy rights
Our CCPA/CPRA Compliance
- Clear privacy notices explaining data collection practices
- Easy opt-out mechanisms for marketing and data sharing
- Tools to help you submit consumer rights requests
- No sale of personal information to third parties
- Reasonable response times (within 45 days) for requests
California Privacy Rights
California residents have specific rights regarding their information. See our Privacy Policy for details on how to exercise these rights.
5. Accessibility Compliance (ADA/WCAG)
Our Accessibility Commitment
ServinYOU is committed to making our platform accessible to individuals with disabilities. We aim to comply with:
- WCAG 2.1 Level AA: Web Content Accessibility Guidelines
- ADA: Americans with Disabilities Act
- Section 508: Federal technology accessibility standards
Accessibility Features
Screen Reader Support
Our interface is compatible with screen readers like JAWS, NVDA, and VoiceOver for visually impaired users.
Keyboard Navigation
Full keyboard navigation without requiring a mouse, with clear focus indicators.
Resizable Text & Colors
Text can be resized without breaking layout, with sufficient color contrast ratios.
Semantic HTML
Proper heading structure, form labels, and semantic markup for assistive technologies.
Accessibility Support
If you experience accessibility barriers, please contact: accessibility@pickngo.com
6. Data Retention & Tax Compliance
Transaction Record Retention
We retain transaction records in accordance with applicable laws:
- Tax Records: 7 years (IRS requirement and industry standard)
- Payment Card Records: 7 years (PCI DSS requirement)
- Customer Information: 2 years after account closure
- Marketing Preferences: Until customer unsubscribes
Your Responsibilities
You remain responsible for:
- Maintaining your own records as required by law
- Tax compliance and reporting to IRS/state agencies
- Downloading and storing reports for your records
- Notifying us of legal retention requirements
Data Deletion Requests
After the required retention period, you can request data deletion. We will permanently delete data within 30 days while maintaining records needed for tax compliance.
7. Food Business Compliance
Important Disclaimer
⚠️ Your Responsibility: ServinYOU does not provide legal or compliance advice regarding food safety, health codes, or licensing requirements. You remain solely responsible for complying with all applicable food safety laws, health regulations, and business licensing requirements in your jurisdiction.
Your Compliance Obligations
As a food truck or restaurant operator, you must ensure compliance with:
- Food Safety Laws: FDA Food Safety Modernization Act (FSMA), state food codes
- Health Permits: Local health department requirements and inspections
- Business Licensing: Federal, state, and local business licenses
- Labor Laws: Minimum wage, overtime, employee classification
- Tax Compliance: Sales tax, income tax, payroll taxes
- Accessibility: ADA requirements for your physical location
- Alcohol Licenses: If applicable, liquor licensing requirements
How ServinYOU Helps
While we don't provide legal compliance, our system helps you:
- Maintain accurate sales records for tax reporting
- Track inventory for compliance audits
- Document payment transactions
- Manage menu items and pricing
- Generate reports for business records
Recommendation
We strongly recommend consulting with:
- Local health department for food safety requirements
- CPA or accountant for tax compliance
- Employment attorney for labor law questions
- Business attorney for licensing and contracts
8. Audits & Certifications
Annual Compliance Audits
- PCI DSS assessment by qualified security assessors
- SOC 2 Type II audit by independent auditors
- Vulnerability assessments and penetration testing
- GDPR/CCPA compliance reviews
Continuous Monitoring
- Monthly security scanning and testing
- Quarterly compliance audits
- Real-time monitoring of systems and logs
- Regular policy and procedure reviews
Audit Reports & Documentation
We maintain comprehensive audit reports and documentation of our compliance efforts. Enterprise customers can request copies of relevant compliance reports under appropriate confidentiality agreements.
Remediation & Improvement
When audits identify opportunities for improvement, we:
- Develop remediation plans
- Implement fixes and enhancements
- Verify corrections through re-testing
- Document all improvements
For compliance-related questions, audit documentation requests, or to discuss specific regulatory requirements:
Email: compliance@servinyou.com
Phone: [Your Phone Number]
Mailing Address: ServinYOU, Compliance Department, [Your Address]
Response Time: We will respond within 5 business days
Compliance Resource Center
We provide resources to help you maintain compliance:
- Documentation and templates
- Compliance guides and best practices
- Links to relevant regulations and authorities
- Training materials for your team
Your Compliance Responsibility
Important: While we maintain our systems in compliance with applicable laws, you remain responsible for:
- Complying with all laws applicable to your business
- Proper use of our system consistent with regulations
- Protecting your login credentials and customer data
- Notifying us of any compliance concerns
- Consulting with legal counsel for your specific jurisdiction
Last Updated: September 2024
This Compliance page is updated regularly to reflect current regulatory requirements and our commitments. Laws change frequently, and we encourage you to stay informed about regulations affecting your business.