Security & Trust

Built to handle real money and real customer data responsibly

SuperTradies moves payments, job records, and customer information for trade businesses every day. This page describes, plainly, how that data is protected, who can access it, and what we do when something needs fixing.

Current practices and certifications

Where something is still underway, we say so rather than implying it is finished.

Active

Encryption in transit and at rest

All data is encrypted using TLS 1.2+ in transit and AES-256 at rest, across databases and backups.

Active

PCI DSS compliant payment processing

Card data is tokenized and handled by Stripe, a PCI DSS Level 1 certified processor. We never store full card numbers.

Active

Daily automated backups

Encrypted backups run daily and are retained for 30 days, with periodic restore testing.

Active

Role-based access control

Field staff see only jobs assigned to them; office roles are scoped separately from admin and billing access.

Active

99.9% uptime target

Infrastructure runs across redundant availability zones. Live status and incident history are posted publicly.

In Progress

Single sign-on for enterprise accounts

SAML-based SSO for larger crews and multi-office accounts, alongside standard email and password login.

In Progress

SOC 2 Type II audit

We are undergoing a formal SOC 2 Type II audit with an accredited third party. Report available on request once complete.

Active

Independent penetration testing

Application and infrastructure testing performed by a third-party security firm, with findings tracked to resolution.

How we handle your data

A short, factual summary of ownership, retention, and third-party sharing.

You own your data
Jobs, customers, invoices, and attachments belong to your business. Admins can export the full dataset at any time from account settings.
Deletion on request
Ask us to close your account and we remove your data from production systems within 30 days, and from backup storage within 60.
A limited, named set of subprocessors
We use a small number of vetted providers to run the service — payment processing, cloud hosting, and message delivery. The current list is available at supertradies.io/subprocessors.
No data resale, ever
We do not sell, rent, or license customer or job data to third parties for advertising or any other purpose.

Security FAQ

How is payment data stored?

SuperTradies does not store full card numbers on its own servers. Payments are tokenized and processed directly through Stripe, a PCI DSS Level 1 certified payment processor, so raw card data never touches our infrastructure.

Can I export or delete my data?

Yes. Account admins can export all job, customer, and invoicing records at any time from account settings. If you close your account, we remove your data from production within 30 days and from backups within 60.

Do you share data with third parties?

We never sell or rent customer data. A limited set of subprocessors — payment processing, hosting, and email or SMS delivery — is used strictly to operate SuperTradies, and each is listed at supertradies.io/subprocessors.

Who has access to customer records?

Access follows the roles you set up: field staff see only the jobs assigned to them, and office staff see records tied to your business. Internal SuperTradies employee access is logged and limited to the support and engineering staff who need it to do their job.

How do I report a vulnerability?

Email security@supertradies.io with details and, if possible, steps to reproduce. We acknowledge reports within two business days and prioritize fixes based on severity.

Security questions or vulnerability reports: security@supertradies.io