Your business.
Your data.
How we protect the information you trust us with.
Separate by design.
Database policies separate one sauna’s customer records from another’s. Protection does not rely on application code alone.
The right access.
Staff access is set by role. Administrative access for support is limited and logged.
Protected information.
Customer data is encrypted in transit and at rest, with automated backups. Card numbers go directly to your payment provider.
Clear about our suppliers.
The application and database are hosted in the EU. Our published sub-processor list names the suppliers we use and their locations.
Something to report?
Security questions and good-faith vulnerability reports are welcome.
security@tighsauna.com