Security & trust
Money, data, continuity — all spelled out
Before you hand over a venue's payments and member data, you should know how they're kept.
Funds security
- Payments go straight to your account. Online payments arrive in your own account via Stripe; the platform doesn't hold or custody funds.
- Idempotent refunds. Cancellation refunds go through the ledger; repeated requests won't over-refund or mis-charge.
- Payment compliance outsourced. Card data never touches our systems; PCI compliance is handled by Stripe.
Data security
- Data resides in Canada. Hosted in ca-central-1 (central Canada).
- Encrypted in transit and at rest. HTTPS end to end, database encryption at rest, daily backups.
- Your data is yours. Members, bookings, stored value and business data export in full at any time, used for nothing beyond this service.
Dedup & the ledger
- Ledger-level arbitration. Overlapping-unit conflicts auto-lock through a single unified projection.
- Database-level constraints. Unique constraints prevent double-booking under concurrency — not check-then-write.
- No negative balances, no double-spend. Balance changes go through the ledger, attributed to each operator.
Local compliance
- PIPEDA. Member personal data is handled under Canadian privacy law.
- CASL. Marketing email carries consent records, a physical address and one-click unsubscribe.
- Biometrics assessed as needed. If facial access control is integrated, a necessity assessment is done separately.
Business continuity
- Source-code escrow. For Flagship, brand website and app source are held with a third party, released if we discontinue.
- API backward-compatible ≥ 12 months. Breaking changes are notified in writing 90 days ahead.
- Orderly exit on termination. Either side gives 60 days' notice; we assist export, and data is retained 90 days for migration.
Want the finer security details?
You can request data-processing and compliance materials when you book a demo.