Last updated: August 18, 2026
Security and privacy are built into how meshnmeet is designed and operated. This page summarizes the measures we take to protect your data and the data of the people who respond to your polls. Questions or concerns? Email security@meshnmeet.com.
Our approach
meshnmeet is a scheduling and opinion polling service, delivered both as a hosted app at meshnmeet.com and as a WordPress plugin you install on your own site. We aim to collect only the data needed to run the Service, to keep it secure, and to be transparent about how it is handled. This page should be read together with our Privacy Policy and Terms of Service.
Encryption
- In transit: all traffic to meshnmeet.com is served over HTTPS/TLS.
- At rest: account passwords are never stored in plain text — they are stored only as salted, hashed values.
- We do not collect or store full payment card numbers (see “Payments” below).
Access controls
Access to production systems and customer data is limited to the people who need it to operate and support the Service, protected by strong authentication. Staff roles in the site-admin backend (Super admin, Admin, Editor, Billing) each have a defined, least-privilege permission scope.
Payments
Payments and subscriptions are processed by our payment provider, Paddle, which acts as the merchant of record and is responsible for PCI-DSS-compliant handling of card data. meshnmeet does not see or store your full card details; we receive only limited billing metadata such as subscription status, plan, and card brand / last four digits.
Sub-processors
We use a small set of vetted providers to operate the Service. Each processes only the data needed for its function:
- Paddle — payments, subscriptions, tax, and invoicing (merchant of record).
- Postmark — transactional and invitation email delivery.
- Cloudflare — bot protection (Turnstile) on public forms.
- Microsoft Clarity — anonymized, input-masked analytics and session replay on meshnmeet.com only.
- Sentry — application error monitoring and diagnostics.
- Our hosting provider — to host the website and store data.
- Backup storage — encrypted/secured backups of the site and database.
A current sub-processor list is available on request, and we will provide reasonable advance notice of material changes to customers who ask to be notified.
Abuse and bot protection
Public sign-up and voting forms are protected by Cloudflare Turnstile, and sensitive endpoints are rate-limited to reduce spam and abuse and to protect shared email-sending reputation.
Backups and continuity
We take regular automated backups of the site and database to external, secured storage (not only the primary host), with retention appropriate to recovery needs, and we periodically test restores.
Privacy and data protection
- We support data-subject rights under laws such as the EU/EEA GDPR and California CCPA/CPRA — access, correction, deletion, and export. Account holders can export or delete their account and data from their account page; see the Privacy Policy for details.
- For business customers who need one, a Data Processing Agreement (DPA) is available — contact privacy@meshnmeet.com.
- Deleted polls are moved to a trash area and permanently deleted after 90 days; billing records are retained as required by law.
- When you install the self-hosted WordPress plugin, poll and participant data are stored in your site’s own database — not on meshnmeet.com — and you act as the controller of that data.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, please email security@meshnmeet.com with details and steps to reproduce, and allow us a reasonable time to investigate and remediate before any public disclosure. Please do not access or modify data that isn’t yours, and avoid tests that could degrade the Service for others.
Certifications
meshnmeet follows widely recognized security and privacy best practices. Formal certifications (such as SOC 2 or ISO 27001) are part of our roadmap and are pursued in line with customer and regulatory needs; current status and any available reports can be requested at security@meshnmeet.com.
Contact
Security: security@meshnmeet.com · Privacy / DPA: privacy@meshnmeet.com · General: hello@meshnmeet.com.