Start free →
🌐 Country / languageEnglish — grabtheslot.comDeutsch — grabtheslot.deMagyar — grabit.hu
Security & data protection

How we protect your customers’ data

GrabTheSlot holds your customers’ names, phone numbers and bookings. This page describes what actually protects that data today — measured facts, not promises.

Last updated: 24 September 2026

What protects your data today

Access & identity

  • Passwords of at least 10 characters, stored as bcrypt hashes — never in readable form.
  • Two-factor authentication (authenticator app) for any user; the owner can make it mandatory for their team. One-time recovery codes, and account lockout after repeated wrong codes.
  • “Sign out of all other devices” also revokes the two-factor trust of remembered devices.
  • Three roles (owner · staff · delegated), with layered permission checks on every action.
  • Two-factor authentication is mandatory for platform administrators. Support access to your account is only possible in a time-limited (8-hour), logged way, and stays visible in the interface throughout.

Separated accounts (tenant isolation)

  • Every database operation runs on the server and is filtered by your business’s identifier — another business’s data cannot be reached from your account.
  • The public keys used in the browser cannot read the data tables: row-level access rules and revoked database privileges protect them.
  • Before every release an automated check runs that fails the release if a database change would open new access.

Data & location

  • The database runs in the EU, in Ireland (Supabase, AWS eu-west-1 region), on encrypted (AES-256) storage.
  • The application server is in the EU, in Finland (Hetzner, Helsinki).
  • All traffic is TLS-encrypted (HSTS enabled).
  • Payment-provider keys and two-factor secrets are additionally encrypted at application level with AES-256-GCM.
  • We store no card data: card payments are handled by Paddle, and booking deposits by your own Barion account.

Backup & recovery

  • Daily database backups at the database provider (7-day retention).
  • On top of that, a weekly provider-independent backup to another provider’s EU-jurisdiction storage — so an account or region outage does not take the backup with it.
  • The independent backup is encrypted before upload (age); the decryption keys are kept separately from the storage.
  • A scheduled, automated test restore verifies that the backup can actually be restored.
  • If a release fails the post-deployment check, the system automatically rolls back to the previous working version.

Operations & updates

  • Firewall, automatic banning after repeated failed logins, key-only server access.
  • Automatic operating-system security updates and a weekly automated security check that alerts on deviations.
  • Weekly automated vulnerability checks of software dependencies; the release tooling is pinned to fixed, verified versions.
  • Type checks and automated tests run before every release — no release if they fail.
  • Critical server-side errors send an automatic alert to the operator.

Data protection (GDPR)

  • The data processing agreement (DPA) is part of the service, not a paid extra.
  • We name every sub-processor (see below) and announce changes 30 days in advance.
  • You can export your data in a machine-readable format; deleting the account ends in anonymisation after a 30-day grace period.
  • Technical logs are deleted automatically after their retention period.

When something goes wrong: incident notice

If we become aware of a security incident affecting your data, we notify you by email within 24 hours at the latest with the information available, and keep you updated. That is early enough for you — as the controller — to notify your supervisory authority within the 72 hours required by the GDPR.

Sub-processors

These providers process data on our behalf. The list is the same as in the data processing agreement — it is generated from a single source.

Sub-processorPurposeData locationTransfer basis
Supabase Inc.Database hosting, authentication, file storage (logos, images)EU (Ireland — AWS eu-west-1 region)Standard Contractual Clauses (SCC)
Hetzner Online GmbHApplication server (serving the booking and admin interface); a separate server runs our self-hosted, cookie-free visit statisticsEU (Finland, Helsinki — application server; Germany, Falkenstein — statistics)EEA
Cloudflare, Inc.Provider-independent backup (a weekly copy of the entire database, for disaster recovery) and DNS serviceEU-jurisdiction storage (R2); US-based providerEU-U.S. Data Privacy Framework (DPF)
GitHub, Inc.Running the automated backup job: the weekly database backup passes through GitHub’s runner environment for the duration of the job (it is not stored there)USEU-U.S. Data Privacy Framework (DPF)
Resend Inc.Sending transactional emails (confirmations, reminders, cancellations, account notices)USEU-U.S. Data Privacy Framework (DPF)
Twilio Inc.Delivering SMS and WhatsApp reminders (phone number + reminder text)
(only if the Controller enables the SMS or WhatsApp reminder add-on)
USEU-U.S. Data Privacy Framework (DPF) + Binding Corporate Rules (BCR)
Zoho Corporation B.V.Support email mailbox (receiving the messages you send us)EU (the provider’s EU data centre)EEA

NIS2

The NIS2 Directive is not expected to apply directly to GrabTheSlot. If your organisation is subject to NIS2, we support your supply-chain security obligations: 24-hour incident notice, named sub-processors, and cooperation in audits. We do not claim NIS2 certification or compliance.

Vulnerability disclosure

If you have found a security issue, please report it to us directly — not publicly. [email protected]

What we commit to

  • We acknowledge your report within 2 business days.
  • We keep you informed about the fix.
  • We take no legal action over good-faith research that follows the rules below.
  • If you wish, we credit you after the fix.

What we ask

  • Do not access, modify or delete other users’ data.
  • Do not run automated scans that load the service, and do not attempt denial of service.
  • Give us reasonable time to fix the issue before disclosing anything publicly.

Related documents

Security contact

Security reports, vendor questionnaires or questions about the DPA:

[email protected]