Data security
We hold your pricing strategy and, if you choose, a connection to your booking system. We describe only what works today.
Encrypted connection
All traffic goes over HTTPS. Your browser is told to connect to us only through an encrypted channel for a year.
Passwords and login
We store passwords only as an irreversible hash, so none of us can read them. A series of failed login attempts locks the account briefly, and changing the password ends all open sessions.
Account isolation
Every data query is limited to your account. Trying to open someone else's resource ends with a “not found” reply, so the reply does not reveal whether such a resource exists. The application connects to the database with a role that has no administrative privileges.
Guest data
We do not store guests' personal data. From an iCal calendar we read only the dates of booked nights, and the Beds24 access code covers prices and properties, without guest data.
Backups
The database is backed up daily, and the backups are encrypted with a key kept off the server. We keep the last fourteen backups.
Servers in the European Union
The application and the database run on a server in France.
Your data, your decision
You export your account data and delete your account yourself in settings. A deleted account disappears from the database at once and from backups within fourteen days.
Reporting vulnerabilities
If you see a security vulnerability, write to the address in the security.txt file. We will check the report and reply.
See it on your own property
No credit card. Cancel any time.