tandoco · trust center

trust at tandoco

Every claim on this page is checkable. The numbers below are read live from our operational systems on every page load — not curated, not updated quarterly. The commitments are the same ones written into our internal kitchen-running playbook.

this page refreshes from live ops on every visit
live ops

how we’re running right now

These numbers come from our production database. They refresh on every page load — what you see is what we see when we open mise each morning.

 
uptime · last 30 days
computing…
 
avg order → delivery time
measured from order placed to ready-for-handoff.
 
refund rate · all-time
no-questions-asked refunds, fully reconciled.
us-central1
data residency
Firestore region · Iowa, USA. SOC 2 Type II.
commitments

what we promise

These aren’t marketing copy — they’re the rules we hold ourselves to internally, surfaced here so you can hold us to them too.

Your data lives in our own Firebase project. We never sell, license, or syndicate customer data to third parties. The only outbound integrations are the ones we operate ourselves to ship you the meal you ordered.
All payments run through Stripe. We never see, store, or transmit raw card numbers. Stripe holds the PCI scope; tandoco only receives a tokenized customer ID and the final amount.
Email + SMS only for what you opted into. Order updates, delivery alerts, and the marketing list are independent opt-ins. Unsubscribing from one doesn’t silently subscribe you to another.
30-day cancellation, no questions. Cancel a subscription any time. Refund within 30 days of your last charge if the food didn’t work for you. We’d rather lose the order than the relationship.
Whole ingredients, scratch-cooked. Every meal is cooked from real, recognizable food. We don’t use mystery powders, fillers, or “natural flavor” stand-ins. Recipes and lot codes are tracked per batch.
Audit trail for every significant write. Every staff write to orders, customers, recipes, and settings is recorded in an append-only log with the actor, the action, and the time. We can reconstruct any change.
verifiable proof

things you can independently check

Below are public signals — not behind our login. You can verify each one against the upstream provider’s system of record.

Stripe merchant tandoco LLC operates as a verified Stripe merchant in good standing. Card-present and card-not-present checkouts both flow through Stripe’s rails. Stripe status page →
Email sender authentication Outbound transactional + marketing email is sent through SendGrid with SPF, DKIM, and DMARC configured for the tandoco.com sender domain. You can verify the DNS records against any public DNS lookup. verify SPF on tandoco.com →
Firestore region Customer data is stored in Google Cloud Firestore us-central1 (Iowa, USA). Google Cloud is SOC 2 Type II certified; tandoco inherits that certification for the storage layer. Firebase status page →
HTTPS only tandoco.com is served over HTTPS exclusively, with HSTS preload and a Let’s Encrypt-issued certificate auto-renewed every 90 days through Firebase Hosting. SSL Labs report →
Webhook signing Partner-facing webhook deliveries are signed with HMAC-SHA256 in the X-Tandoco-Signature header, so a receiver can authenticate the origin of every event we send.
Append-only audit log Significant writes inside mise (our internal admin) are recorded in an append-only audit log with strict Firestore rules: even staff with write access cannot rewrite or delete an existing entry.
audit trail

last 24 hours on the record

We don’t expose individual entries on this public page, but we do publish the volume — how many significant writes happened across mise in the last 24 hours.

 
significant writes recorded across mise in the last 24 hours. Each entry captures the actor, the action, the affected collection, and the fields touched. Server-side rules block updates and deletes — once written, an entry is permanent.
last refreshed just now · numbers above are read live on every page load