Security & trust

Built to be trusted with your bookings, guests, and payouts.

Operators hand us their operation. Here are the controls that protect it — described as they actually work today, not as aspirations.

Tenant isolation

Every operator's data is isolated at the database level by row-level security. Access requires membership in that operator's organisation — one operator can never see another's bookings, guests, or finances.

Least-privilege access

Application code runs under row-level security. The privileged role that can bypass it is ring-fenced in code to an explicit, audited set of jobs and admin paths, enforced automatically in our build. Platform staff are a separate role from operators.

Tamper-evident admin log

Actions taken by platform staff are written to an append-only audit log that cannot be edited or deleted — enforced by the database itself, not just by policy.

Payments handled by Stripe

Card details are collected by Stripe and are never stored by Experiencefront. Payments run on Stripe Connect, with each operator as the account holder.

Privacy by default

Analytics stay off until you consent. For abuse prevention we store a salted one-way hash of IP — not the raw address (infrastructure providers may still log IP at the network layer). New sub-processors are posted at least 30 days before they start.

Careful AI data handling

AI is used only to help operators draft listing copy — never to process guest personal information — and only vendors contractually bound to zero-retention, no-train terms ever receive personal information.

Operator vetting

Operators verify their identity through Stripe's onboarding checks. Business, insurance, and permit documents are held in a private, staff-only vault.

Reliability & backups

Application data and payments run on managed infrastructure (Supabase and Stripe) that provides storage durability and routine backups. Further specifics are available on request.

Where your data lives

Your data is processed by a small set of vetted providers — including Supabase, Stripe, Resend, and Cloudflare. We publish the full list and post new providers at least 30 days in advance.

View our sub-processors →

Responsible disclosure

If you believe you've found a security vulnerability, please email us and give us a reasonable chance to fix it before disclosing publicly. We'll work with you in good faith.

[email protected]

Have a security or compliance question? Read our Privacy Policy or get in touch.