Security

How GoCushy keeps money and data safe

The short version: we never hold your money, we never see card numbers, and the parts of the system that move money are the most heavily tested code we own. The longer version is below, in plain language — because a security page you can't understand isn't one you can trust.

We never hold your money

Every payment on GoCushy settles directly from the buyer to the merchant through the payment provider the merchant connects — their own Stripe, PayPal, Airwallex, or BlinkPay account. Funds never pass through a GoCushy bank account, and there is no GoCushy wallet or balance. We are checkout software, not a custodian: if GoCushy disappeared tomorrow, your money would already be exactly where it belongs.

We never see card numbers

Card details are entered into, and processed by, the payment provider's own secure fields on the checkout page. Card numbers never touch GoCushy's servers, are never stored by us, and never appear in our logs. The PCI-regulated handling of card data sits with the providers built for it.

Pay-by-bank never sees your bank login

Where pay-by-bank is offered, you approve the payment at your own bank — GoCushy and the merchant never see your bank credentials, and the payment moves only after you approve that exact amount at your bank. This is New Zealand open banking working as designed.

How we protect data

How we test it

The money path is guarded by an automated test suite of more than 3,500 tests that runs before every deployment, in multiple configurations. On top of that we run adversarial security audits of our own systems — reviewers whose only job is to break the money path before anyone else can. The August 2026 security audit confirmed 31 findings; all 31 were fixed and re-verified on production. New payment rails additionally go through a full rehearsal on a staging environment — real end-to-end payments, refunds included — before they are enabled for anyone.

Reporting a vulnerability

If you believe you have found a security issue in GoCushy, we want to hear about it — please email security@gocushy.com with enough detail to reproduce it. We will acknowledge your report within two business days, keep you informed as we fix it, and credit you if you would like. We ask that you give us reasonable time to fix an issue before disclosing it publicly, and that testing never involves other people's data or money. A machine-readable version of this policy lives at /.well-known/security.txt.

Who we are

GoCushy is operated by Daom Limited, New Zealand company number 9403442, NZBN 9429053427724, registered office Flat 6, 25 Broderick Road, Johnsonville, Wellington 6037, New Zealand — verifiable on the NZ Companies Register. Questions about anything on this page: hello@gocushy.com.

Last updated 21 August 2026.