← Farmooly
Security & Privacy
Last updated July 26, 2026 · Questions: info@farmooly.com
Your farm listings, SNAP-related badges, orders, and payment details deserve real protection — not marketing fluff.
You are safe to take this seriously
Farmooly is operated by Family Farms Forever LLC, doing business as Farmooly in Maryland. We treat cybersecurity and privacy as product requirements — not afterthoughts. Below is what we do in plain language, and how to reach us if something looks wrong.
Report a vulnerability
Email info@farmooly.com with a description and steps to reproduce. Please do not post exploits publicly. Good-faith research is welcome. We aim to acknowledge within 2 business days.
Our baseline protections
- Encryption in transit — connections to our hosted sites and APIs use HTTPS (TLS), as provided by Firebase Hosting and Google Cloud.
- Encryption at rest — data stored in Firebase/Firestore is encrypted at rest by Google Cloud with Google-managed keys (standard Firebase platform protection).
- Signed-in access control — Firebase Authentication and Firestore security rules are used so private records are not left world-readable; access is limited by design to the account (or linked roles such as parent/teacher) that should see them.
- Secrets stay out of the app binary — server-side API keys and payment secrets are stored in Google Cloud Secret Manager (or equivalent cloud config) for Cloud Functions — not hardcoded into the public client apps.
- Payments by specialists — card payments are processed by Square, Stripe, Apple In-App Purchase, and/or Google Play Billing depending on the transaction. Our design is that full card numbers (PAN) are not stored in our application databases.
- No sale of personal data — we do not sell your information to data brokers or ad networks.
- Account deletion — available in-app or by request so you can leave cleanly.
- Metered public APIs — public machine-readable APIs include rate limits (and optional API keys with usage metering) so automated bulk access is constrained.
Specific to Farmooly
- Vendor vs shopper separation — private operational fields (emails, payment-account identifiers, push tokens, raw USDA FNS numbers) are never exposed on the public AI/local-food API.
- SNAP honesty — a vendor’s public SNAP badge only shows when acceptance is recorded under our rules (including FNS authorization where required). We never publish the raw FNS number.
- Payments — Square handles connected in-person Tap to Pay transactions and eligible single-vendor app checkout, while Stripe supports multi-vendor, web, and backup payment paths. Farmooly does not store full card numbers.
- Location — used to help you find nearby markets and farms; we do not sell location profiles.
- Public API — rate-limited free tier; higher volume requires a key so abuse is measurable.
Full legal detail: Privacy Policy.
Marketing site analytics
The Farmooly marketing website may use privacy-aware analytics (with consent tooling where required). That is separate from selling personal data to brokers. See the Privacy Policy for processors. The product’s private vendor/shopper fields remain off the public local-food API.
What we do not claim (yet)
- We may not yet have a published SOC 2 letter for this product.
- We do not currently run a paid public bug-bounty program.
- When a third-party penetration test is completed, we will note it here.
We would rather be honest than over-promise. The engineering practices above are real and continuously maintained.
Related
Farmooly is operated by Family Farms Forever LLC, doing business as Farmooly in Maryland. Security contact: info@farmooly.com.