Last updated: 23 July 2026
Security at Breeze
Breeze handles restaurant operations, guest feedback, and connected-platform data. We design access around the organization, brand, and location, and apply safeguards appropriate to an early-stage business software platform.
Connected accounts
- Breeze uses OAuth for Google Business Profile and does not ask customers to share Google passwords.
- We request only the access needed for the user-facing integration and keep tokens separate from public application code.
- Customers can revoke connected-platform access and request deletion at any time.
Application and infrastructure
- Encrypted HTTPS connections are used for the website and application.
- Production secrets are kept in managed environment bindings rather than source code.
- Access to production systems is limited to people who need it to operate or support the service.
- Logs and operational records are used to investigate failures, abuse, and unauthorized access.
Product controls
- Connected locations are limited to profiles the signed-in user is authorized to manage.
- Review replies and profile changes require specific customer authorization; Breeze does not silently publish automated changes.
- Organization and location boundaries are part of the product's access model as multi-tenant functionality is rolled out.
Vulnerability reports
If you believe you found a security issue, email [email protected] with the affected URL, steps to reproduce, and potential impact. Please do not access or alter data that is not yours. We will acknowledge good-faith reports and work to resolve confirmed issues.
Current posture
Breeze does not claim a security certification we have not earned. As the product and customer base grow, we will formalize vendor reviews, access reviews, incident response, backups, and independent assurance. Questions from a customer's security or procurement team can be sent to [email protected].