Skip to main content
Joove
Joove
NearbyFindLeaderboardList Item
☕
Map
PostSign In
Joove

From Kerbside to Community. Australia's real-time map for community reuse — giving every unwanted item a second life.

Platform

  • Explore Map
  • List an Item
  • How It Works
  • Support Us

Company

  • About Joove
  • Terms
  • Privacy
  • Contact

Get in Touch

info@joove.app

Based in Australia 🇦🇺
Serving communities nationwide

© 2026 JOOVE™ by 100 Founts Pty Ltd. All rights reserved.

Built with for the planet

Security Policy

Last updated: March 2026 — Vulnerability Disclosure & Security Practices

Found a security issue?

Please report it responsibly to security@joove.app — do not disclose it publicly until we have had a chance to address it.

1. Our Commitment to Security

JOOVE takes the security of our platform and the privacy of our users seriously. We implement industry-standard security measures including:

HTTPS/TLS encryption on all connections
Supabase Auth with Row Level Security (RLS)
Sentry error monitoring and alerting
Stripe PCI-compliant payment processing
Security headers (CSP, HSTS, X-Frame-Options)
Regular dependency updates and audits

2. Vulnerability Disclosure Policy

We welcome responsible disclosure from security researchers. If you discover a vulnerability in JOOVE, please follow these guidelines:

  • Report privately first. Email your findings to security@joove.app before any public disclosure.
  • Include enough detail for us to reproduce the issue: steps to reproduce, affected URL or endpoint, potential impact, and any proof-of-concept code or screenshots.
  • Do not access, modify, or delete data that does not belong to you. Test only against your own account.
  • Do not perform denial-of-service attacks, spam, phishing, or social engineering against JOOVE users or staff.
  • Give us reasonable time to investigate and fix the issue before any public disclosure (see response timelines in Section 3).

3. Response Timelines

Initial acknowledgementWithin 2 business days

We confirm receipt of your report and provide a reference number.

Triage & assessmentWithin 5 business days

We assess severity (Critical / High / Medium / Low) and begin investigation.

Fix deploymentWithin 30 days for Critical/High

We aim to patch critical issues within 30 days. Medium/Low issues within 90 days.

Disclosure coordinationAfter fix is deployed

We will notify you when the fix is live and coordinate any public disclosure.

4. Safe Harbour

JOOVE will not pursue legal action against security researchers who discover and responsibly disclose vulnerabilities in accordance with this policy. We consider responsible disclosure a valuable contribution to our security posture. This safe harbour applies provided the researcher: (a) acts in good faith, (b) does not access or harm user data beyond what is necessary to demonstrate the issue, and (c) reports to us before any public disclosure.

5. Scope

This policy applies to the following JOOVE systems:

  • joove.app and all subdomains
  • JOOVE API endpoints (api.joove.app)
  • JOOVE mobile PWA

Out of scope: third-party services (Supabase, Stripe, Vercel, PostHog) — please report vulnerabilities in those services directly to their security teams.

6. Data Breach Notification

In the event of a data breach involving personal information, JOOVE will notify affected users and, where required, the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. We aim to notify within 30 days of becoming aware of a qualifying breach.

7. Contact

Security reports: security@joove.app
General privacy: privacy@joove.app

Privacy Policy →Terms of Service →