Trust — Lunga
Lunga — Security (pre-launch)
Last updated: September 15, 2026
Payments
Card details are entered into and processed by a licensed payment provider in Indonesia. Card numbers never reach Lunga's servers. Lunga receives a confirmation and a masked reference only.
Contact details stay private
Guests and vendors communicate through the app. Vendors see an order code and a delivery address, not a guest's phone number or email, and guests see a vendor's business name, not a personal number.
Authentication & session security
Sign-in is handled through Supabase Auth, using Google sign-in or email. Session tokens are stored using device-level secure storage.
Data access rules
Each role sees only its own data: a guest sees their own orders, a vendor sees the orders assigned to them, and a property manager sees orders at their own properties. These rules are enforced in the database, not only in the app.
Encrypted transit
All data sent between the app and our servers is encrypted using HTTPS/TLS.
Reporting a vulnerability
If you discover a security vulnerability in Lunga or any Paradigm Shift Apps product, please email MAIL so we can investigate and address it promptly.