Snapshot 36606
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Security Policy PickUp — pipedriveclickup.com Last updated: February 2026 1. Our Commitment to Security At PickUp, operated by e-hoster.co.uk Ltd, the security of your data is a priority. This Security Policy outlines the measures we take to protect your account, your data, and the integrity of the PickUp service. We continuously review and improve our security practices to keep pace with evolving threats. If you have a security concern or wish to report a vulnerability, please see Section 7. 2. Data Transmission All data transmitted between your browser and our service is encrypted in transit using HTTPS and TLS (Transport Layer Security). This applies to all pages of pipedriveclickup.com, your account dashboard, and all API communications with Pipedrive and ClickUp. We do not permit unencrypted HTTP connections to any part of the service. 3. Password Security We never store your password in plain text. All passwords are salted and hashed before being stored, meaning that even in the unlikely event of a data breach, your actual password cannot be recovered from our systems. We recommend that you: Use a strong, unique password for your PickUp account Avoid reusing passwords across multiple services Use a reputable password manager to manage your credentials securely Never share your account password with anyone 4. Third-Party Integrations PickUp connects to your Pipedrive and ClickUp accounts using OAuth 2.0, the industry-standard authorisation protocol. This means we never see or store your Pipedrive or ClickUp passwords. Access is granted via secure tokens, which you can revoke at any time from within your Pipedrive or ClickUp account settings. Payment processing is handled entirely by Stripe, a PCI DSS-compliant payment provider. We do not store your full card details on our systems at any point. 5. Security Audits and Testing We conduct regular security audits and penetration testing to proactively identify and address potential vulnerabilities in our infrastructure and application code. Findings from these assessments are reviewed and remediated in order of severity. Our internal development practices include code reviews and security-conscious development standards to reduce the introduction of vulnerabilities at the source. 6. Infrastructure Security The PickUp service is hosted on cloud infrastructure located in the United States or the European Union. Enterprise plan customers may request EU-only data residency. Our hosting environments are managed with access controls, monitoring, and industry-standard hardening practices. Access to production systems and customer data is restricted to authorised personnel only, on a need-to-know basis. 7. Reporting a Vulnerability We welcome responsible disclosure from security researchers and users. If you believe you have discovered a security vulnerability in PickUp, please contact us directly rather than disclosing it publicly. We will investigate all reports promptly and work to resolve confirmed issues as quickly as possible. When reporting a vulnerability, please include: A clear description of the issue and its potential impact Steps to reproduce the vulnerability Any supporting screenshots, logs, or proof-of-concept material Please do not attempt to access, modify, or delete data that does not belong to you during your research. We ask that you give us a reasonable amount of time to investigate and respond before any public disclosure. 8. Data Breach Response In the event of a confirmed data breach that affects your personal data, we will notify affected users within 72 hours of becoming aware of the incident. Where required, we will also notify the Information Commissioner's Office (ICO) in accordance with our obligations under UK GDPR. Breach notifications will include a description of what happened, what data was affected, the steps we have taken to contain the incident, and any actions we recommend you take to protect yourself. 9. Your Responsibilities While we work hard to keep the service secure, security is a shared responsibility. To help protect your account, we ask that you: Keep your login credentials confidential and do not share them with others Log out of your account when using shared or public devices Notify us immediately if you suspect any unauthorised access to your account Ensure that the Pipedrive and ClickUp accounts you connect to PickUp are themselves secured appropriately 10. Changes to This Policy We may update this Security Policy from time to time as our practices evolve. When we make material changes, we will update the "Last updated" date at the top of this page and notify you where appropriate. We encourage you to review this page periodically. 11. Contact Us For security concerns, vulnerability reports, or any questions about this policy, please contact us at: e-hoster.co.uk Ltd pipedriveclickup.com Email: support@pipedriveapps.com