Navigated to Security page
    Skip to main content

    Trust

    Security at Hiba Gifts

    How we protect the platform, who processes data on our behalf, and how to reach us about a security concern.

    Last updated: 13 July 2026

    1. How we protect the platform

    Hiba Gifts is operated by Synergaid Pty Ltd (ABN 63 682 263 001). Security is built into how the platform runs day to day, not bolted on. The practices below are in place today.

    • Donation, ledger, and audit records are append-only. They cannot be edited or deleted through the application once written.
    • Access to data is restricted row by row in the database, so donors, charities, and administrators can each see only what belongs to them.
    • Administrator access is protected by multi-factor authentication, enforced on the server, and every administrative action is written to an audit log.
    • Automated checks run around the clock. They reconcile payments, verify ledger balances, screen charity partners against sanctions lists, and alert us when anything drifts from its expected state.
    • The database is backed up continuously by our hosting provider, with point-in-time recovery available.

    2. How payments are handled

    Card details are captured and processed by our accredited payment providers and never reach Hiba Gifts servers. Payment amounts, references, and outcomes are recorded so every donation can be traced through to the charity, and automated reconciliation compares our records against the payment provider daily.

    3. Privacy controls for donors and recipients

    • Gift recipients never see the donation amount unless the donor chooses to share it.
    • Donors can export or delete their personal data themselves from account settings, through a tracked request process.
    • Optional analytics only run after a visitor consents through the cookie banner, and the choice can be changed at any time.

    4. Sub-processors

    These providers process data on our behalf to run the platform. The list is maintained in our vendor register and updated here when it changes.

    Loading the current list.

    5. Reporting a security concern

    If you believe you have found a security weakness in Hiba Gifts, we want to hear from you. Email support@hibagifts.com with a description of the issue and steps to reproduce it. Machine-readable contact details are published at /.well-known/security.txt.

    We ask that you act in good faith.

    • Do not access, modify, or delete data that is not your own.
    • Do not degrade the service for donors or charities while testing.
    • Give us a reasonable opportunity to investigate and fix the issue before sharing it publicly.

    We acknowledge reports within two business days and will keep you informed as we investigate. We do not pursue good-faith researchers who follow these guidelines.