Candyll
NearbyDealsLog In

On this page

  • 1. About This Policy
  • 2. Definitions
  • 3. Your Part: Keeping Your Account Safe
  • 4. Merchant Staff Credentials
  • 5. Our Part: How We Protect Your Account
  • 6. Candyll Does Not Handle Your Payment Details
  • 7. Things We Will Never Do
  • 8. Reporting Suspicious Account Activity
  • 9. Security Incidents and Notification
  • 10. Responsible Disclosure of Security Vulnerabilities
  • 11. How This Policy Fits With Other Documents
  • 12. Changes to This Policy
  • 13. Contact
← All legal documents

Account Security Policy

Version 2.1 · Last updated: July 17, 2026

Operated by Boryne Labs Ltd. (operating as 'Candyll') · Contact: customersupport@candyll.com

These documents are provided in English. If a translation is ever offered, the English version governs.

On this page▾
  • 1. About This Policy
  • 2. Definitions
  • 3. Your Part: Keeping Your Account Safe
  • 4. Merchant Staff Credentials
  • 5. Our Part: How We Protect Your Account
  • 6. Candyll Does Not Handle Your Payment Details
  • 7. Things We Will Never Do
  • 8. Reporting Suspicious Account Activity
  • 9. Security Incidents and Notification
  • 10. Responsible Disclosure of Security Vulnerabilities
  • 11. How This Policy Fits With Other Documents
  • 12. Changes to This Policy
  • 13. Contact

1. About This Policy

This Policy explains, in plain language, how you and Candyll each help keep your account safe. It covers what we ask of you, what we do on our side, how to report a problem, and what happens if a security incident occurs. Candyll never collects or stores your payment or card details (see Section 6), so keeping your account secure is about protecting your sign-in, not any money held by Candyll.

This Policy is one of the Policies incorporated into the Candyll Terms of Service. Your binding duties around your account and credentials are set out in the Terms of Service; this Policy adds practical guidance and describes our security commitments and how to reach us about security issues. It does not expand or reduce the rights and obligations in the Terms of Service, and nothing in it limits any right you have under applicable law that cannot be waived.

2. Definitions

  • Candyll, we, us — Candyll, operator of the candyll.com website and the Candyll mobile app (together, the "Platform").
  • Customer — an individual with a Candyll account who browses, joins, or redeems Deals.
  • Merchant — a business listed on the Platform that offers Deals and is the seller in every transaction.
  • Merchant Staff — an individual granted manager or staff access to a Merchant's account under the Merchant's authority.

Other capitalized terms have the meanings given in the Terms of Service.

3. Your Part: Keeping Your Account Safe

Your account is protected by your email address and password. Please:

  1. Choose a strong, unique password. Use a password you do not use anywhere else. A password manager makes this easy.
  2. Keep it to yourself. Do not share your password or any sign-in code with anyone — including people who claim to work for Candyll. We will never ask for it (see Section 7).
  3. Keep your email account secure. Your email is used to reset your password, so anyone who controls your email can reach your Candyll account.
  4. Sign out on shared devices. If you use a public or shared computer or phone, sign out when you are done.
  5. Keep your contact details current. We use the email on your account to reach you about security matters.
  6. Tell us right away if something looks wrong. See Section 8 for how to report suspicious activity.

4. Merchant Staff Credentials

If you are a Merchant owner, you are responsible for the people you invite to your account. Give each team member their own login — never share one set of credentials across staff. Remove access promptly when someone leaves your team. Sensitive functions on a Merchant account (such as team management and any account-level financial or billing settings for Candyll's own fees) are available to the account owner only. Candyll does not process, hold, or pay out the Merchant's customer sales proceeds — customers pay the Merchant directly at the store — so a Merchant account has no customer-payment, payout, or settlement surface to secure. The full rules for Merchant Staff access are in the Merchant Terms.

5. Our Part: How We Protect Your Account

We take the following measures, described here in plain terms:

  1. We never store your password in readable form. Passwords are kept solely as one-way cryptographic hashes. Our team cannot see your password, and we cannot email it to you.
  2. We keep passwords out of our logs. Our systems are designed so that passwords and sign-in codes are not written into application logs or error reports.
  3. We help you use a strong password. We encourage you to choose a long, unique password that you do not use on any other service, and we provide the guidance in Section 3 to help you keep your account secure.
  4. Your connection is encrypted. Traffic between your device and the Platform is encrypted in transit using TLS.
  5. Least-privilege access for our team. Our staff and contractors can access personal data only where their role requires it, under access controls, and their access is limited to what is needed for the task.
  6. We monitor for abuse. We use technical safeguards designed to detect and limit suspicious sign-in and account activity.

Security can never be absolute, and no online service can promise that incidents will never happen. Section 9 describes what we do if one does.

6. Candyll Does Not Handle Your Payment Details

Candyll never processes, collects, or stores your payment or card details. You do not pay Candyll for Deals: there is no checkout, no saved card, and no stored payment method on the Platform. When you redeem a Deal Pass, you buy directly from the Merchant and pay the Merchant, normally in person at the store, using the Merchant's own payment methods — so your card or payment details go to the Merchant's own point of sale, never to Candyll. Because Candyll holds no card number, no payment token, and no stored value, there is nothing about your payment for us to lose in a security incident. For how the Merchant handles your in-store payment, receipt, and any refund, see the Merchant Terms and the Cancellation, Redemption & Refund Policy; for how we handle personal information generally, see the Privacy Policy.

7. Things We Will Never Do

To help you spot impostors, here is what Candyll will never do:

  • We will never request your password or a sign-in code — by email, phone, text, chat, or in person.
  • We will never ask you to send us money for a Deal — by e-transfer, gift card, wire, or any other method. Candyll never collects payment for a Deal; you pay the Merchant directly at the store.
  • We will never ask you to install remote-access software to "fix" your account.
  • We will never threaten to close your account unless you hand over credentials or money.

If anyone does any of these while claiming to be Candyll, do not respond — report it to us using Section 8.

8. Reporting Suspicious Account Activity

If you notice sign-ins you do not recognize, changes you did not make, or any activity on your account you did not authorize:

  1. Change your password right away if you can still access your account.
  2. Contact us at customersupport@candyll.com with as much detail as you can (what you saw, when, and on which device).
  3. We will investigate. We review credible reports of unauthorized account activity. While we investigate we may secure the account (for example, by ending active sessions or temporarily locking sign-in) to protect you.
  4. Outcomes. If we confirm your account was accessed without authorization, we will act to secure it. Candyll does not process payments and cannot charge you, so there is no Candyll charge to reverse or refund. If you see a charge you do not recognize from a Merchant you paid at a store, that is a matter between you, that Merchant, and your bank or card issuer — contact them directly. Nothing in this Policy limits your rights with your bank or card issuer, or any other right you have under applicable law.

9. Security Incidents and Notification

We maintain an internal incident-response process. If we become aware of a security incident affecting the Platform, we will work to contain it, assess what happened and who is affected, and fix the cause.

If an incident affects your personal information and creates a real risk of significant harm, we will notify you, and the appropriate regulators, as required by applicable law, and we will tell you what happened, what information was involved, and what steps you can take. We keep records of security incidents as the law requires. More detail on how we protect personal information is in the Privacy Policy.

10. Responsible Disclosure of Security Vulnerabilities

If you are a security researcher (or just an observant user) and you believe you have found a security vulnerability in the Platform, we want to hear from you.

  • Report it privately to customersupport@candyll.com with enough detail for us to reproduce the issue.
  • Give us reasonable time to fix it before sharing the issue publicly.
  • Stay in bounds. Do not access, modify, or delete data that is not yours; do not degrade or disrupt the service; do not use social engineering, phishing, or physical attacks; stop and report as soon as you can demonstrate the issue.
  • Good faith is respected. If you follow these rules in good faith, we will not initiate legal action against you for your research, and we will work with you constructively.
  • We do not currently operate a paid bug-bounty program; any recognition or reward is at our discretion.

11. How This Policy Fits With Other Documents

These documents form one agreement. This Policy governs the topic of account-security guidance, our security commitments, and the security reporting channel; on that topic it prevails over the Terms of Service. The Terms of Service govern your binding account duties and everything not covered by a Policy. Nothing in any document limits rights you have under applicable law that cannot be waived — if any provision conflicts with such a right, the right prevails. This Policy is incorporated into the Terms of Service and carries its own version and effective date.

12. Changes to This Policy

We may update this Policy from time to time, for example to describe new protections. The current version always applies, and material changes will be announced with reasonable advance notice as described in the Terms of Service.

13. Contact

Security reports and account-security questions: customersupport@candyll.com Privacy questions: privacy@candyll.com Legal notices: admin@candyll.com