Trust — Lunga

Lunga — Security (pre-launch)

Last updated: September 15, 2026

Lunga is in development and has not been released. This page describes the security measures being built in, and will be updated with the final details before launch.

Payments

Card details are entered into and processed by a licensed payment provider in Indonesia. Card numbers never reach Lunga's servers. Lunga receives a confirmation and a masked reference only.

Contact details stay private

Guests and vendors communicate through the app. Vendors see an order code and a delivery address, not a guest's phone number or email, and guests see a vendor's business name, not a personal number.

Authentication & session security

Sign-in is handled through Supabase Auth, using Google sign-in or email. Session tokens are stored using device-level secure storage.

Data access rules

Each role sees only its own data: a guest sees their own orders, a vendor sees the orders assigned to them, and a property manager sees orders at their own properties. These rules are enforced in the database, not only in the app.

Encrypted transit

All data sent between the app and our servers is encrypted using HTTPS/TLS.

Reporting a vulnerability

If you discover a security vulnerability in Lunga or any Paradigm Shift Apps product, please email MAIL so we can investigate and address it promptly.