Stow Cards Wallet passes

Security

How we protect your data

A plain-English summary of how the platform is actually built. No badges, no jargon. For personal data, see the privacy policy.

Security at a glance

Token-based auth

Short-lived, signed tokens on every request. Passkeys and SSO supported.

Signed service calls

Internal services only trust requests signed by our gateway.

Tenant-scoped data

Every request is scoped to your merchant account in the request pipeline.

Server-only credentials

Wallet signing credentials and pass tokens never leave our servers.

Last updated 29 September 2026.

Authentication

Sign-in traffic is verified centrally and issued short-lived, cryptographically signed tokens (RS256). Merchant accounts can federate sign-in through SSO instead of a stored password, and passkey sign-in is supported. Cookie-based sessions are protected with CSRF tokens on every state-changing request.

One gateway, signed internal calls

Every browser request enters the platform through a single public gateway. Individual backend services are never reachable directly from the internet. The gateway authenticates the caller and mints a signed header that downstream services independently verify before doing any work, so a service cannot be tricked into trusting a request that did not come through the gateway. Internal-only routes are rejected outright at the public edge, whatever credentials are presented.

Wallet pass credentials

Each Apple Wallet pass carries its own authentication token, generated at enrollment. That token is stored server-side only and is never included in any API response a browser or app can read. Only the wallet device itself ever sees it, exactly as Apple's and Google's wallet specifications require. The certificates and keys used to sign passes stay on our servers.

NFC tap payloads

Where NFC tap-to-redeem is enabled, the payload a pass sends to a terminal is not a plain code. Both Apple Wallet's VAS protocol and Google Wallet's Smart Tap encrypt the exchange, and the payload carries an HMAC-tagged member identifier rather than a raw Member ID, so a leaked tag can be revoked without rotating anyone's pass. NFC is opt-in per platform; Apple's NFC entitlement and Google's Smart Tap certification are in progress, and redemption requires compatible terminal hardware on your side. See NFC tap-to-redeem for details.

Tenant-scoped data access

Merchant data is scoped by tenant on every request. A logged-in user can only read or write the merchant accounts they are explicitly permitted for, and the check is enforced in the request pipeline rather than left to individual screens.

Encryption and data handling

Traffic to the platform is encrypted in transit with TLS. Monetary values, points balances, and prices are stored as integers in minor units rather than floating-point decimals, so balances never drift from rounding. The platform and its backups run in the UK, in Amazon Web Services’ London region, and connections are encrypted all the way to our servers there.

Personal data and GDPR requests

You, the merchant, are the controller of your members’ data; Stow Cards processes it for you and acts on your instructions. See the privacy policy for details.

Certifications

We do not yet hold formal security certifications. Formal certification is on our roadmap, and this page will state exactly what we hold once we do. Until then, we would rather describe plainly what we actually build than decorate the footer with badges.

Reporting a concern

If you believe you have found a security issue, email hello@stow.cards with details before disclosing publicly. We acknowledge reports and work with you on a fix.