Legal / Compliance
Information Security Policy
Last updated: August 2, 2026 · Effective for VenueCore Systems operations and customer-facing platforms
VenueCore Systems (“VenueCore,” “we,” “us,” or “our”) maintains this Information Security Policy to document how we identify, mitigate, and monitor information security risks relevant to our business software platforms, websites, and messaging services (including SMS delivered through providers such as Twilio).
1. Purpose and scope
This policy applies to:
- VenueCore websites, including venuecoresystems.com
- Business software platforms we operate for accounting, operations, service, and office workflows
- Customer and prospect communications, including SMS opt-in programs
- Systems, credentials, vendors, and personnel that handle VenueCore or customer data
2. Security ownership
The VenueCore Systems owner is responsible for approving this policy, assigning access, reviewing incidents, and ensuring security procedures remain operational. Day-to-day security controls are enforced through platform configuration, access restrictions, vendor settings, and documented operating procedures.
Security questions: support@venuecoresystems.com
3. Risk identification
We identify information security risks relevant to our business, including:
- Unauthorized access to customer or business accounts
- Exposure of personal contact data (name, email, phone number)
- Misuse of messaging channels or unauthorized SMS sending
- Payment-data handling risks in accounting and billing workflows
- Vendor or hosting failures, misconfiguration, or service abuse
- Loss of availability due to missing backups or failed restore readiness
Risks are reviewed when systems change, new vendors are added, incidents occur, or before customer go-live decisions.
4. Access control procedures
- Production and administrative access is limited to authorized personnel.
- Protected application routes require authenticated user, company, and tenant context where applicable.
- Credentials and owner keys are treated as sensitive; sharing is restricted.
- Access is reviewed when roles change or when an owner readiness / security review is performed.
- Public marketing pages are separated from internal application tooling where practical.
5. Data protection procedures
- Personal information is collected only as needed to operate platforms, support customers, and honor messaging consent.
- SMS phone numbers are used only for programs the recipient opted into and related support.
- We do not sell mobile phone numbers.
- For offline card workflows, full card numbers and CVV are not stored in VenueCore systems.
- Where online payment processors are used, at most one active online processor may be enabled; zero active online processors is an allowed secure configuration.
- Data retention follows business, consent-proof, support, and legal needs as described in our Privacy Policy.
6. Vendor and third-party risk
We use vetted service providers for hosting, messaging, and related operations. Providers such as Twilio may process phone numbers and message metadata solely to deliver services on our behalf. Vendor access is limited to the service function required. Material vendor changes are reviewed for privacy, security, and messaging-compliance impact.
7. Monitoring and mitigation
- We maintain application health checks, readiness reviews, audit/logging paths, and owner review gates before customer use where the platform requires them.
- Security and payment policy reviews are used to confirm controls before production customer onboarding.
- Backup and restore readiness is part of production readiness review.
- Tenant isolation and role-based access controls are verified as part of platform acceptance testing.
- Suspicious access, abuse, or messaging misuse is investigated and mitigated promptly.
8. Incident response procedure
- Detect: Identify the issue through alerts, user reports, vendor notices, or internal review.
- Contain: Restrict access, disable affected credentials or integrations, and stop unauthorized messaging if needed.
- Assess: Determine systems, data types, and parties affected.
- Remediate: Apply fixes, rotate credentials, restore from backup if required, and verify recovery.
- Notify: Contact affected customers and, where required, relevant providers or authorities.
- Improve: Update controls and this policy if gaps are found.
To report a security concern, email support@venuecoresystems.com.
9. Messaging and communications security
- SMS is sent only after express opt-in (checkbox never pre-checked).
- STOP opt-out and HELP requests are honored.
- Consent records are retained to demonstrate lawful messaging enrollment.
- Message content is limited to the program categories disclosed on our website and in our Privacy Policy.
10. Employee / operator expectations
- Use strong unique passwords and protect administrative sessions.
- Do not store payment card PAN/CVV in VenueCore systems.
- Do not send SMS without documented consent.
- Report suspected incidents immediately to support@venuecoresystems.com.
- Follow least-privilege access and avoid sharing owner credentials.
11. Policy review
This Information Security Policy is reviewed at least annually, and sooner after material system changes, security incidents, or new regulatory/provider requirements (including messaging-provider compliance reviews). The published version on venuecoresystems.com is the current customer-facing reference.
12. Related documents
13. Contact
VenueCore Systems
Website: https://venuecoresystems.com
Email: support@venuecoresystems.com