Breeders trust us with their contact details, photos of their animals and conversations with buyers. Below we describe specifically how we protect that data. We list only measures that are actually in place — no generalities.
§ 1. Encrypted connection
The entire service runs over HTTPS only. Unencrypted connections are automatically redirected to the encrypted version, and the browser receives an HSTS header valid for one year, covering subdomains as well. After the first visit your browser refuses an unencrypted connection on its own, even if someone hands you such a link.
We also send headers that limit common classes of attack: a ban on embedding the service in a frame on a foreign domain, a block on browser content-type sniffing, and a restriction on how much referrer information is passed to other sites.
§ 2. Passwords and account access
We do not store passwords. We keep only their hash computed with bcrypt at cost 12 — a function designed to be deliberately slow to attack. Even if the database leaked, recovering a password from such a hash is practically infeasible. For the same reason we cannot read or tell you your password; we can only let you set a new one.
Two-factor authentication is available. We recommend enabling it to anyone selling on the platform.
The session cookie is marked as inaccessible to scripts and limited to our domain, which makes hijacking a logged-in session harder.
§ 3. Payments
We do not store card numbers, CVV codes or any other data that would allow charging your account. Payments are handled entirely by Stripe, an operator compliant with the PCI DSS standard. You enter card details directly with them and those details never reach our servers. On the ReptiMarket side we keep only a transaction identifier needed to link the payment to your account.
§ 4. Your data and your control over it
We process data in accordance with the GDPR; details are described in our Privacy Policy.
You can delete your account together with your data at any time using the option in your profile settings. We additionally confirm deletion by e-mail, so that nobody can erase an account without your knowledge after gaining brief access to a logged-in browser.
§ 5. Backups
We back up the database and files daily and automatically. Backup health is monitored by a separate job, and older copies are cleaned up on a schedule. A server failure therefore does not mean losing your listings or photos.
§ 6. Reporting vulnerabilities
If you find a security flaw, write to us through the contact form marking your message "security". Please do not disclose the finding publicly before we have had a chance to fix it. We treat such reports as a priority and are happy to credit by name anyone who helps us make the service safer.
We do ask you not to run tests that could harm other users: bulk data scraping, denial-of-service attacks or actions on other people's accounts.