Security
Security and Compliance
Clickaio handles salon business data and customer contact information. We design our systems so that payment card data never enters them.
Cardholder data
- Clickaio does not store, process or transmit primary account numbers.
- Card data is captured by certified payment terminals and transmitted directly to the processing partner.
- Clickaio receives only transaction results and reference identifiers.
Data hosting
- PostgreSQL on Supabase, hosted in the United States.
- Application hosted on Vercel.
- Data encrypted in transit and at rest.
Tenant isolation
- Every salon's data is separated at the database level using PostgreSQL row-level security.
- Isolation is enforced by the database itself rather than by application code.
Access control
- Role-based permissions for every staff member.
- Administrative access is separate from salon staff access.
- Sensitive actions are written to an audit log.
Messaging compliance
- Registered A2P 10DLC campaigns for business text messaging.
- Explicit consent captured before any marketing message.
- Automatic opt-out handling.
- Spoken disclosure before call recording.
Privacy
- A documented data retention schedule.
- Customer data access and deletion requests supported.
- De-identification rather than raw retention where records must be kept.
Incident response
- A documented breach response plan with defined notification steps.
Monitoring
- Centralized application error reporting.
- A health endpoint monitoring production availability.
Security or compliance questions? Contact support@clickaio.com
Contact us