Built to handle real money and real customer data responsibly
SuperTradies moves payments, job records, and customer information for trade businesses every day. This page describes, plainly, how that data is protected, who can access it, and what we do when something needs fixing.
Current practices and certifications
Where something is still underway, we say so rather than implying it is finished.
Encryption in transit and at rest
All data is encrypted using TLS 1.2+ in transit and AES-256 at rest, across databases and backups.
PCI DSS compliant payment processing
Card data is tokenized and handled by Stripe, a PCI DSS Level 1 certified processor. We never store full card numbers.
Daily automated backups
Encrypted backups run daily and are retained for 30 days, with periodic restore testing.
Role-based access control
Field staff see only jobs assigned to them; office roles are scoped separately from admin and billing access.
99.9% uptime target
Infrastructure runs across redundant availability zones. Live status and incident history are posted publicly.
Single sign-on for enterprise accounts
SAML-based SSO for larger crews and multi-office accounts, alongside standard email and password login.
SOC 2 Type II audit
We are undergoing a formal SOC 2 Type II audit with an accredited third party. Report available on request once complete.
Independent penetration testing
Application and infrastructure testing performed by a third-party security firm, with findings tracked to resolution.
How we handle your data
A short, factual summary of ownership, retention, and third-party sharing.
- You own your data
- Jobs, customers, invoices, and attachments belong to your business. Admins can export the full dataset at any time from account settings.
- Deletion on request
- Ask us to close your account and we remove your data from production systems within 30 days, and from backup storage within 60.
- A limited, named set of subprocessors
- We use a small number of vetted providers to run the service — payment processing, cloud hosting, and message delivery. The current list is available at supertradies.io/subprocessors.
- No data resale, ever
- We do not sell, rent, or license customer or job data to third parties for advertising or any other purpose.
Security FAQ
SuperTradies does not store full card numbers on its own servers. Payments are tokenized and processed directly through Stripe, a PCI DSS Level 1 certified payment processor, so raw card data never touches our infrastructure.
Yes. Account admins can export all job, customer, and invoicing records at any time from account settings. If you close your account, we remove your data from production within 30 days and from backups within 60.
We never sell or rent customer data. A limited set of subprocessors — payment processing, hosting, and email or SMS delivery — is used strictly to operate SuperTradies, and each is listed at supertradies.io/subprocessors.
Access follows the roles you set up: field staff see only the jobs assigned to them, and office staff see records tied to your business. Internal SuperTradies employee access is logged and limited to the support and engineering staff who need it to do their job.
Email security@supertradies.io with details and, if possible, steps to reproduce. We acknowledge reports within two business days and prioritize fixes based on severity.
Security questions or vulnerability reports: security@supertradies.io