Security
Last updated: July 30, 2026
OutfitterHub is built to protect your business data and your clients' personal information. Here's how we keep it safe.
Your data is isolated by account
Every outfitter's data is walled off from every other account. Access is enforced at the database level using row-level security, so an account can only ever read or write its own bookings, clients, invoices, documents, and payments — not just in the app, but in the database itself. Within your account, access is further controlled by team roles and permissions, and every request is authenticated.
We can't see your data unless you let us.
OutfitterHub support has no standing access to your workspace — your clients, bookings, and finances are visible only to you. If you ever want hands-on help, you can grant support a time-limited (72-hour), read-only access window from your own settings, revoke it at any time, and every access is logged where you can see it.
Encryption
All data is transmitted over encrypted HTTPS connections, and your data is encrypted at rest in our cloud database and file storage.
Passwords and sign-in
Passwords are securely hashed and are never stored in plain text. We also support passwordless magic-link sign-in. Sessions use short-lived tokens that refresh securely.
Credentials and secrets
All system credentials, API keys, and secrets are kept in protected server-side environment variables. Only public, browser-safe keys are ever sent to your browser.
Documents and files
Contracts, waivers, signed documents, licenses, and uploaded photos are stored in private, encrypted storage and are shared only through authorized, expiring links. Documents are private by default.
Payments
Card payments are processed by Stripe, a PCI-DSS Level 1 certified payment provider. Full card numbers never touch our servers — Stripe handles cardholder data directly. Where you use Stripe Connect, payout credentials and connected-account data are also handled by Stripe under their security controls. Practice / test mode uses Stripe's test environment so trial activity does not create live charges.
Email and SMS
Transactional and campaign email is sent through our email delivery pipeline. SMS (when enabled) is sent through Twilio. We store suppression and SMS opt-out records so promotional email and SMS respect unsubscribe and STOP requests for messages sent through OutfitterHub. Public forms that accept inquiries may use Cloudflare Turnstile to reduce automated abuse.
Optional AI features
AI tools (help assistant, Content Studio, campaign recommendations, document tagging) only run when you use them. The content needed for that request is sent to our AI gateway under server-side credentials; we do not use that content to train third-party models. Review AI output before sending it to clients or attaching it to contracts.
Backups and recovery
Your data is backed up regularly so it can be restored if it's ever lost — for example, after an accidental deletion, hardware failure, or a service outage. Backups are encrypted and access-controlled exactly like your live data, and are removed in line with our data-retention practices when you close your account.
Privacy
We never sell or rent your data. See our Privacy Policy for how we collect, use, and protect personal information, and our Terms of Service for how the platform may be used.
Reporting a concern
Found a possible security issue, or have a question about how we handle your data? Email us at support@outfitterhub.ca and we'll respond promptly.