SECURITY AND PAYMENTS
Protection, reviews and reporting
A clear route to protect accounts, data and subscriptions and quickly resolve an unrecognised charge.If you suspect fraud, contact your bank or card issuer immediately and notify Swissync. Never send passwords, one-time codes or full card details.Unrecognised charge
Check the SWISSYNC descriptor and salon subscriptions. Tell us the salon, amount, date and last four digits of the payment method—never the full card number.
- Contact the bank or issuer immediately if fraud is suspected.
- Retain your case reference and avoid duplicate requests.
- We review contractual and technical evidence with Stripe and authorised partners.
Phishing
Swissync never asks for passwords, verification codes, PINs, e-banking credentials or transfers to accounts sent by message. Check the swissync.org domain.
- Never disclose SMS or authenticator codes.
- Do not install remote-control software at a stranger’s request.
- Forward suspicious messages to support@swissync.org.
How we protect the service
We use salon separation, role-based access, revocable sessions, signed Stripe webhooks, protected server keys, payment idempotency and security logs. Swissync does not store full card data.
- A technical signal alone does not establish identity.
- Material decisions can be reviewed.
- Controls evolve with risk.
Responsible reporting
Describe the behaviour, URL, date, device and minimum steps. Do not access other people’s data, disrupt the service or publish details before our review.
Incidents
We contain impact, preserve necessary evidence and follow applicable duties under Swiss data-protection law.
