Our position
We are a small, new brand. We are not going to claim enterprise security certifications we do not have. What we can tell you is exactly what we do, and what we do not hold.
The strongest security control we have is that we hold very little. No payment cards. No passwords. No identity documents. No behavioural tracking data. Data you never collect cannot be stolen from you.
How the site is protected
- HTTPS is enforced on every request, with HSTS and preloading.
- A strict Content Security Policy blocks third-party scripts. The browser is not permitted to contact any external service on our behalf.
- Clickjacking, MIME-sniffing and referrer leakage protections are set at the response-header level.
- Camera, microphone, geolocation and payment browser APIs are switched off by policy.
- Every form input is validated on the server before anything is stored. Nothing is trusted from the browser.
- Form endpoints are rate-limited, with a hidden honeypot field and a timing check to reject automated submissions.
- Our CRM credentials are held only on the server. They are never sent to your browser, and the Content Security Policy would block the browser from using them even if they were.
Access to your data
Access to the CRM is limited to the people who need it to run the business, each with their own account and multi-factor authentication enabled. Collection and return are booked through a Careem or Uber courier per job, so no third party holds an account here or a standing copy of customer data — each booking passes only the address and mobile number that job needs, never the full customer record.
If there is a breach
If personal data is exposed, we will contain it first, then assess what was affected, then notify. Under the PDPL we notify the UAE Data Office without undue delay, and we will tell affected people directly where there is a risk to them.
We will tell you what happened, what data was involved, what we have done, and what you should do. We will not minimise it or wait for it to be discovered.
Reporting a vulnerability
Found a problem? Email security@waxytaxy.com with enough detail to reproduce it. We will acknowledge within 3 working days.
We will not pursue legal action against anyone who reports a genuine vulnerability in good faith, gives us reasonable time to fix it, and does not access, alter or exfiltrate other people's data in the process. We cannot pay a bounty at this stage, and we will not pretend otherwise — but we will credit you if you would like that.
What will change when we start selling
- Card payments will be handled entirely by a licensed payment gateway. Card numbers will never touch our servers.
- Order and address data will enter the picture, and this page and the Privacy Policy will be updated before that happens.
- The controls above are a baseline for a pre-launch site, not a finished security programme for a trading business.