Security and trust
Your people's data, handled with care
Thankscrate reads the minimum it needs to run your program, keeps it inside your company's walls, and relies on partners whose security programs are audited. Here is what that means, in plain language.
Read-only HR access
Thankscrate can read, never write, in your HR or payroll system.
Only what a gift needs
Name, email, dates, title, department, status, shipping address. Nothing else is read.
Only your company sees your data
Every request is checked against your company membership. No other business can reach it.
Card details stay with Stripe
Cards are entered in Stripe's hosted form. Thankscrate keeps brand, last four, expiry.
Controls
What we do, specifically
Read-only HR access
The payroll connection can read, never write. Thankscrate cannot create, edit, or delete anything in your HR or payroll system.
Only the data a gift needs
Name, work email, birthday, start date, title, department, status, and shipping address. Compensation, tax IDs, bank details, reviews, and photos are never requested.
Your company's data stays yours
Every request is checked against your company membership. No other business can reach your people's data, by design.
Encrypted connections and credentials
Traffic is encrypted in transit. The tokens that connect your payroll system, suppliers, and sign-in providers are stored encrypted.
Cards stay with Stripe
Cards are entered in Stripe's hosted form. Thankscrate stores the brand, last four digits, and expiry, nothing more.
Accounts that protect themselves
Passwords are screened against known breaches, sessions expire when idle, and recipient links are signed and time-limited. Or sign in with Google or LinkedIn.
How it runs
Operated like software, because it is
How the platform is hosted, released, and watched.
Managed cloud hosting
Production runs on managed cloud infrastructure, separate from the environments where changes are tested.
Every change is checked before it ships
Static analysis, type checks, automated tests, a dependency audit, and custom guardrails run on every change before it can be released.
Monitored around the clock
Errors, failed jobs, and every scheduled task report to monitoring with documented severity levels and runbooks. Names, emails, and addresses are redacted before anything reaches those tools.
Recorded and verified
Order and event changes, password changes, and every support session are logged. Inbound webhooks are signature-checked, and recipient links are signed and expire.
Where we are
SOC 2 readiness, no audit yet
Thankscrate is formalizing its security program toward a SOC 2 Type II audit and will publish the report here when it is complete. The partners that store or process customer data on our behalf hold their own certifications today: Stripe (PCI DSS Level 1 and SOC 2 Type II), and Finch, Shopify, and OpenAI (SOC 2 Type II). Bring us your checklist and we will answer every question directly.
- A security overview, a data-flow summary for the HRIS connection, and answers to your security questionnaire are available on request
- Reach the security contact at info@thankscrate.com
Partners
Where your data goes
Four partners handle customer data on Thankscrate's behalf. Each gets only what its job needs. The full subprocessor list is available on request.
- Finch
Reads your HR roster, read-only, and nothing outside the fields a gift needs. SOC 2 Type II.
- Stripe
Holds card details and issues invoices and receipts. PCI DSS Level 1.
- Suppliers and Tango
The supplier shipping a physical gift receives the recipient's name and address for that gift. Tango receives a name and email for a gift card.
- OpenAI
Drafts messages on accounts that turn the assistant on. It sees the recipient's first name and the occasion, not your roster.
Questions
Security questions
The short answers. We answer questionnaires in full.
Is our HR data secure?
Thankscrate reads only what it needs to send a gift. That is name, email, birthday, start date, title, department, employment status, and shipping address. It never reads compensation, tax IDs, or bank details, and it never writes to your payroll. Data moves over TLS, and access is scoped to your company by design. See the Security page for the full picture.
Who at Thankscrate can see our data?
Only the people supporting your account, and every support session is logged. The internal tools Thankscrate staff use to look up platform data are read-only, and each lookup is recorded. Business users can only ever reach their own company's data.
Where do our employees' shipping addresses go?
To the supplier fulfilling that gift, and to an address verification service before anything ships. A supplier sees the recipient's name and address for that gift only. Gift card recipients get an email, so no address is involved.
Do you store our card details?
No. Cards are entered in Stripe's hosted form and never touch Thankscrate. We keep the card brand, the last four digits, and the expiry so you can recognize the card on your receipts.
Do you use AI on our data?
Only to draft gift messages, on accounts that have the assistant turned on. The draft request carries the recipient's first name and the occasion, not your roster or anything from your HR system. OpenAI does not train its models on data sent through its API.
Do you support single sign-on or multi-factor authentication?
Sign in with Google or LinkedIn is available today. SAML single sign-on and multi-factor authentication for password accounts are not in place yet. Ask us where they sit on the plan.
Are you SOC 2 certified?
Not yet. Thankscrate is formalizing its security program in preparation for a SOC 2 Type II audit. The vendors that handle your data (Stripe, Finch, Shopify, and others) are SOC 2 Type II certified today.
How do I report a security concern?
Email info@thankscrate.com with the details and we will respond directly. Errors and failed jobs report to monitoring around the clock, with documented severity levels and runbooks for how the team responds.
Send us your security questionnaire
We answer it in full, walk through data handling and the HRIS authorization flow, and give you a straight answer to every question on your checklist.