NF / Legal / Fresto
Fresto — Security
Access model
Fresto operates within Fresto and requests only the permissions its documented job requires: Order ahead from local shops and pick up without queueing. If a feature would need broader access, the feature is redesigned or dropped — not silently granted.
Data handling
Operational data is limited to what the product needs to function (see the product privacy policy). No sale of customer data, no advertising use, encrypted transport throughout.
Vulnerability handling
Report security issues affecting Fresto via the support form (category Security) or the process on our security page. Reports are acknowledged and handled with coordinated disclosure.
What we don't claim
We do not claim SOC 2, ISO 27001 or similar certifications for Fresto. If that changes, scope and dates will be stated here. [Placeholder — requires legal review.] confirm audit or assessment status with the team before launch.
Last updated: 2026-08-20.