Trust & Safety
Data security
Ubuntu Pool is built with security at every layer. Here is how we protect your personal data and payment information.
Encrypted connections (TLS)
All data transmitted between your browser and Ubuntu Pool is encrypted using TLS 1.3, the same standard used by banks. You will always see a padlock icon in your browser address bar when using our platform.
Payment data handled by Pesapal
We never store your card number, CVV, or mobile money PIN. All payment data is handled directly by Pesapal, a PCI-DSS Level 1 compliant payment processor. This is the highest level of payment security certification.
Passwords are hashed
Your password is never stored in plain text. We use bcrypt hashing, a one-way algorithm, so even Ubuntu Pool staff cannot see your password. If you forget it, it must be reset, not retrieved.
Data stored in secure infrastructure
All platform data is stored on encrypted servers hosted in secure data centres. Data at rest is encrypted using AES-256. Regular backups are taken and stored in separate locations.
Access controls
Only authorised Ubuntu Pool staff can access user data, and only when necessary for support or compliance purposes. All staff access is logged and audited.
Reporting a security issue
If you discover a security vulnerability in Ubuntu Pool, please report it responsibly to security@ubuntupool.com. Do not publicly disclose the issue until we have had a chance to investigate and fix it. We take all security reports seriously.
Tip
Use a strong, unique password for your Ubuntu Pool account and enable two-factor authentication if available. Never share your login credentials with anyone.