Section 01
Scope of This Security Overview
This Security Overview applies to the capture 5 website,
landing pages, checkout pages, onboarding, client
communications, managed reputation services, customer
information handling, reporting, support, billing
workflow, and related business systems.
This Security Overview should be read together with the
capture 5 Terms of Use, Privacy Policy, Cookie Policy,
Email Terms, Opt-Out Policy, Disclaimer, Review Platform
Disclaimer, Data Processing Addendum, Campaign Agreement,
checkout terms, and applicable accepted service
documents.
This page is a general overview. It is not an insurance
policy, legal opinion, audit report, penetration-test
result, certification, compliance report, or guarantee of
absolute security.
Section 02
No Security Certification Claim
This page does not represent that capture 5 has obtained a
particular security certification, independent audit,
government authorization, or regulatory approval.
Unless capture 5 provides a separate current written
document expressly confirming otherwise:
-
No SOC 2 certification or audit result is claimed.
-
No ISO 27001 certification is claimed.
-
No PCI DSS certification by capture 5 is claimed.
-
No HIPAA, FedRAMP, HITRUST, or similar certification is
claimed.
-
No third-party security endorsement is implied.
-
No government approval is implied.
-
No review-platform partnership or special security
status is implied.
A future audit, certification, questionnaire, or security
report will apply only to the scope, systems, date, and
conditions expressly identified in that document.
Section 03
Information capture 5 Is Designed to Handle
capture 5 is designed to provide managed reputation
services using limited first-party customer information
supplied by the client business.
- Customer first name and last name.
- Customer email address.
-
Limited service or location context when needed,
appropriate, and approved for the service.
-
Email delivery, unsubscribe, suppression, bounce,
complaint, and operational service status.
-
Review, response, monitoring, or customer concern
information where included in the selected plan and
supported by available systems.
-
Client business contact information for authorized
users, owners, managers, billing contacts, and service
contacts.
-
Payment status, transaction references, invoices,
account balances, and billing records processed through
authorized business and payment systems.
The standard customer information model is limited to the
information reasonably needed to provide, secure,
document, and support the authorized reputation service.
Section 04
Data Minimization and Prohibited Information
capture 5 is not designed to receive unnecessary,
sensitive, regulated, or high-risk customer information.
Clients should provide only the minimum information needed
for the authorized service.
-
Do not submit health information, medical details,
treatment notes, diagnosis information, patient
information, appointment details, or protected health
information.
-
Do not submit complete payment-card numbers, bank
account numbers, credit reports, Social Security
numbers, passport numbers, tax identifiers, government
identifiers, or insurance identifiers.
- Do not submit information about children.
-
Do not submit passwords, login credentials,
authentication codes, biometric information, or precise
location information.
-
Do not submit unnecessary information concerning race,
ethnicity, religion, political opinions, union
membership, genetic information, sexual orientation,
criminal history, or other legally sensitive categories.
-
Do not submit purchased, rented, scraped, brokered,
cold-prospect, competitor, or unrelated lists.
capture 5 may reject, delete, isolate, quarantine,
suppress, restrict, or stop processing prohibited
information without automatically waiving valid payment
obligations owed by the client.
Section 05
Access Controls and Internal Handling
capture 5 may use reasonable access controls intended to
limit business-system access to personnel, contractors,
vendors, and service providers who need access to support
the service relationship.
-
Access may be limited by role, need, system permission,
vendor control, account status, or service requirement.
-
Password-protected accounts, administrative controls,
multifactor authentication, permission settings, or
access restrictions may be used where available and
appropriate.
-
Access may be limited, changed, or revoked when
personnel, vendor, account, or service needs change.
-
Personnel and contractors with access to service
information may be subject to confidentiality
expectations or obligations.
-
Access may be investigated, restricted, or removed when
misuse, fraud, nonpayment, breach, or security concerns
arise.
Available access controls depend partly on third-party
systems, vendor functionality, client permissions,
account configuration, and the security features
available within the systems being used.
Section 06
Technical and Organizational Safeguards
capture 5 may use reasonable technical and organizational
safeguards appropriate to the nature of the services, the
limited customer information being processed, and the
business systems supporting the service.
-
Use of established hosting, email, customer relationship
management, payment, form, storage, reporting, security,
and business technology providers.
-
A limited customer-information model centered on names,
email addresses, and operational service information.
-
Suppression and unsubscribe handling intended to reduce
unwanted future email.
-
Operational review of delivery, bounce, complaint, and
list-quality information where available.
-
Maintenance of records reasonably needed for billing,
legal, tax, security, fraud prevention, suppression,
account support, and dispute purposes.
-
Internal handling practices intended to reduce
unnecessary access to or exposure of client-provided
customer information.
Safeguards may change as capture 5 updates its systems,
vendors, legal requirements, service structure, security
needs, and operational practices.
Section 07
Vendors, Subprocessors, and Service Providers
capture 5 may use third-party vendors, subprocessors,
contractors, and professional service providers to
operate, host, secure, deliver, bill, monitor, improve,
and support the services.
- Email delivery providers.
-
Customer relationship management and automation
providers.
- Website hosting and landing-page providers.
-
Form, onboarding, storage, reporting, and communication
providers.
-
Payment processors, checkout providers, fraud-screening
providers, and billing systems.
-
Analytics, security, customer support, and business
operations providers.
-
Professional advisers, contractors, and operational
vendors.
Providers may process information according to their own
security practices, privacy policies, contractual terms,
infrastructure, and technical limitations.
capture 5 may add, replace, or remove providers for
service quality, availability, security, compliance,
performance, cost, or operational reasons.
Independent provider outages, restrictions, system
changes, incidents, or practices outside capture 5’s
reasonable control remain subject to the applicable law
and accepted written agreements.
Section 08
Payment Security and Card Handling
capture 5 may use third-party payment processors,
checkout providers, recurring billing systems,
fraud-screening tools, and subscription-management
systems to process payments, recurring charges, invoices,
failed payments, disputes, and chargebacks.
-
Payment providers may collect and process payment-card
details under their own security standards, policies,
and payment-network rules.
-
capture 5 does not need to store complete payment-card
numbers directly within its own website systems.
-
Payment providers may use device information,
transaction history, billing details, fraud-screening
signals, and payment credentials to process and secure
transactions.
-
Clients are responsible for keeping payment methods
current, accurate, authorized, and protected from
unauthorized use.
-
Failed payments, blocked charges, payment disputes, and
chargebacks are governed by the Campaign Agreement,
Terms of Use, checkout terms, and applicable order
documents.
Payment security is shared among capture 5, payment
processors, card networks, financial institutions, client
payment methods, and checkout systems.
Section 09
Email Security and Deliverability
capture 5 provides email-based customer review outreach
and may use third-party email delivery, automation,
customer relationship management, reporting, and
suppression systems.
-
Email delivery may involve service providers,
automation systems, hosting, domain configuration,
suppression records, bounce records, complaint records,
and delivery monitoring.
-
capture 5 may monitor bounces, complaints,
unsubscribes, invalid addresses, delivery warnings, and
list-quality signals where available.
-
capture 5 may suppress, reject, or stop sending to
addresses that appear invalid, risky, unsubscribed,
complained about, bounced, duplicated, or improperly
sourced.
-
capture 5 may pause or limit sending when a client list
creates material deliverability, legal, privacy,
platform, security, or reputation risk.
-
Email delivery, inbox placement, spam filtering,
customer opens, clicks, responses, and review outcomes
are not guaranteed.
Section 10
Review Platform Security Boundaries
capture 5 may direct customers to approved review
destinations, but independent review platforms control
their own accounts, authentication, security,
publishing, moderation, filtering, ranking, privacy
settings, and enforcement decisions.
-
capture 5 does not control Google, Facebook, Yelp,
Better Business Bureau, Trustpilot, or other independent
review platforms.
-
capture 5 does not control platform login security,
account access, review publication, filtering, removal,
verification, or profile suspension decisions.
-
Clients are responsible for securing their review
platform accounts, business profiles, credentials,
user permissions, and administrative access.
-
Customers who follow an independent review link are
subject to the privacy, security, and account practices
of that platform.
Section 11
Client Security Responsibilities
Security is a shared responsibility. Clients must take
reasonable steps to protect their systems, accounts,
customer information, staff access, review profiles,
payment methods, and communication channels.
-
Provide only lawful, accurate, first-party customer
names and email addresses.
-
Do not submit sensitive or unnecessary customer
information.
-
Use reasonably secure methods to send customer
information and account details.
-
Protect credentials, billing access, email inboxes,
review platform accounts, and administrative
permissions.
-
Promptly report suspected unauthorized access,
incorrect information, prohibited information,
opt-outs, privacy requests, or security concerns.
-
Limit access to reports, links, checkout records,
customer information, and service materials to
authorized personnel.
-
Keep payment methods current, authorized, and protected
from unauthorized use.
-
Train staff not to request fake reviews, review gating,
sentiment filtering, or improper handling of customer
information.
Client-side failures, employee actions, compromised client
accounts, incorrect customer information, lost client
credentials, review-platform misuse, and insecure client
systems remain the client’s responsibility except where
applicable law or an accepted agreement states otherwise.
Section 12
Security Incident Response
When capture 5 becomes aware of a confirmed security
incident involving client-provided customer information
that requires notice under applicable law or an accepted
written agreement, capture 5 will use reasonable efforts
to investigate, contain, document, and notify the affected
client without undue delay following confirmation and
appropriate internal review.
-
Notice may be sent to an account, privacy, security,
billing, or service contact maintained for the client.
-
capture 5 may provide reasonably available information
about affected information, likely consequences, and
responsive measures where appropriate and lawful.
-
The client is responsible for determining whether
notice to customers, regulators, insurers, platforms,
employees, or other parties is required.
-
capture 5 may preserve logs, records, communications,
provider notices, and other information needed to
investigate, document, or respond to the incident.
-
Notice of an incident is not an admission of liability,
fault, contractual breach, negligence, or legal
violation.
Incidents caused by client systems, client personnel,
client contractors, client devices, client credentials,
client instructions, review platform accounts, financial
institutions, or systems outside capture 5’s control
remain subject to the client’s responsibilities and
applicable law.
Section 13
Information Retention and Deletion
capture 5 may retain information for as long as
reasonably necessary to provide services, operate the
business, comply with law, manage payments, resolve
disputes, honor opt-outs, maintain suppression records,
prevent fraud, support security, and protect legal rights.
-
Client account, contract, invoice, tax, payment,
chargeback, and collection records may be retained for
legitimate business and legal purposes.
-
Customer service information may be retained during the
service relationship and for a reasonable period
afterward for operational, legal, audit, suppression,
dispute, backup, and security purposes.
-
Unsubscribe and suppression records may be retained to
prevent future unwanted email.
-
Backup copies may remain until overwritten or deleted
through ordinary backup cycles.
-
Aggregated or de-identified operational information may
be retained for security, service improvement, and
business analysis.
A deletion request does not require deletion of records
that may lawfully be retained for billing, accounting,
tax, security, fraud prevention, suppression, audit,
dispute, backup, chargeback, collection, or enforcement
purposes.
Section 14
International Information Processing
capture 5 operates from the United States, including New
Jersey.
Serving businesses across the United States, United
Kingdom, Canada, Australia, New Zealand, Ireland, and
English speaking countries may involve information being
processed, stored, accessed, or transferred across
national borders.
-
Client-provided customer information, website
information, billing records, support records, and
operational information may be processed in the United
States or other countries where authorized providers
operate.
-
The client authorizes processing and transfers
reasonably necessary to provide the services.
-
Clients outside the United States are responsible for
confirming that their use of a United States-based
provider is lawful.
-
Appropriate contractual, technical, organizational, or
transfer safeguards may be used where required by
applicable law.
-
Country coverage means service support. It does not mean
capture 5 maintains an office, legal entity, tax
registration, government approval, or review-platform
partnership in every market.
Section 15
Business Continuity and Availability
capture 5 uses third-party systems and service providers
to support its website, checkout, payments, email,
customer relationship management, storage, reporting,
and client communications.
Availability may depend on those providers, internet
conditions, financial institutions, email systems,
hosting systems, client cooperation, and other conditions
outside capture 5’s direct control.
-
Website availability is not guaranteed to be
uninterrupted.
-
Checkout availability is not guaranteed to be
uninterrupted.
-
Email delivery and inbox placement are not guaranteed.
-
Third-party provider uptime is not guaranteed.
-
Review-platform, review-link, and platform-account
availability are not guaranteed.
capture 5 may pause, delay, reroute, modify, or reschedule
operational work when reasonably necessary because of
provider outages, deliverability concerns, compliance
review, payment issues, security concerns, platform
changes, or client delays.
Section 16
Security Reviews and Client Requests
Clients may request reasonable information about capture 5
security practices for procurement, vendor review,
privacy assessment, or internal risk review.
-
Requests must be written, specific, reasonable, and
connected to the client’s use of the services.
-
capture 5 may respond with summaries, written answers,
policy excerpts, public security materials, provider
information, or other reasonable documentation.
-
capture 5 is not required to provide source code,
credentials, confidential architecture, internal
security configurations, unrelated client information,
confidential provider terms, employee interviews,
facility access, penetration-testing access, or
vulnerability-scanning access.
-
capture 5 may decline requests that create security,
confidentiality, privacy, operational, legal,
contractual, trade-secret, or provider risk.
-
Separately accepted custom, technical, legal, audit,
procurement, or vendor-review work may have an
additional fee.
Section 17
Security Limitations and No Absolute Guarantee
No company, website, payment system, email system,
hosting provider, customer relationship management
platform, cloud service, employee process, vendor system,
or internet transmission can be guaranteed completely
secure.
capture 5 may use reasonable safeguards but does not
guarantee protection against every possible event or
threat.
- No guarantee against unauthorized access.
-
No guarantee against phishing, malware, credential
theft, social engineering, or provider compromise.
-
No guarantee against client-side security failures.
-
No guarantee against independent review-platform
incidents.
-
No guarantee against payment-provider outages,
chargeback activity, or fraud-screening errors.
-
No guarantee against email filtering, blocking, or
delivery failure.
-
No guarantee against internet outages, system outages,
provider failures, natural disasters, or other events
outside reasonable control.
Security is managed through reasonable safeguards,
limited information, vendor controls, and shared
responsibility. Absolute security is not promised.
Section 18
Relationship to Other Legal Terms
This Security Overview works together with the
Terms of Use
,
Privacy Policy
,
Cookie Policy
,
Email Terms
,
Opt-Out Policy
,
Disclaimer
,
Review Platform Disclaimer
,
Data Processing Addendum
,
Campaign Agreement, checkout terms, and applicable
accepted service documents.
If this Security Overview conflicts with a mutually
accepted written agreement, the more specific accepted
agreement controls for the applicable client relationship
and subject matter.
Billing, payment, renewal, cancellation, refund,
chargeback, service-term, and collection matters remain
governed by the Campaign Agreement, Terms of Use,
checkout terms, and applicable order documents.
Section 19
Updates to This Security Overview
capture 5 may update this Security Overview to reflect
changes in systems, providers, services, security
practices, legal requirements, business operations, or
risk-management practices.
Updates will be posted with a revised effective date.
Material changes apply prospectively unless applicable
law or an accepted agreement permits different treatment.
Section 20
Contact capture 5
Questions about this Security Overview, a vendor-review
request, or a suspected security issue may be sent using
the contact information below.
Use the subject line “Security Question” for a general
question, “Vendor Security Review” for a procurement
request, or “Security Concern” when reporting a suspected
issue.