Your data is yours. Here's exactly how it's protected.

Real answers, not a compliance-theater checklist. Here's what we actually do to keep your lodge's data safe.

Encrypted in transit and at rest

Everything moves over HTTPS. Your database is encrypted at rest, and sensitive tokens (like third-party account connections) get a second layer of encryption at the application level.

Your lodge's data is isolated from every other lodge's

Isolation is enforced at the database engine itself, not just in application code. No customer can query another customer's data. Platform staff access data only for support and troubleshooting.

Role-based access and an audit trail

Every team member gets only the access their role needs — Owner, Manager, Staff, or Guide. Every change to a booking, charge, or guest record is logged with who made it, when, and what changed.

Encrypted daily backups, checked on every run

A backup runs automatically every day and is encrypted before it's stored. Every run restores the data from that backup into a separate test database and checks each table's rows against the snapshot it was made from. If anything doesn't match, we're alerted.

Your guests' card details never touch our servers

Card numbers are handled directly by our payment processor. Outfttr never holds your money and never sees or stores full card details.

Monitoring and alerting

Errors, failed background jobs, and service problems are caught automatically and routed to an alert — not discovered because a guest called in to complain.

Rate limiting and bot protection on public forms

Login, signup, and other public forms are protected against automated abuse, so a scripted attack can't hammer them.

Export anytime, no data hostage

Full data export — guests, reservations, charges, and reports — available any time from Settings. Leave whenever you want. No penalty, no waiting on us.

Where your data lives

Your data is hosted in the United States. We tell you and your guests that in writing rather than leaving it implied. The full list of service providers we use to run Outfttr, and where each one operates, is in our Privacy Policy.

Questions Canadian lodges ask

Is Outfttr PIPEDA compliant?

There's no such certification — PIPEDA obligations belong to your lodge, not to us. We built Outfttr to support your PIPEDA obligations: encryption, access controls, an audit trail, and clear written terms on how we process your data.

Where exactly is our data stored?

On servers located in the United States. Canadian privacy law allows this with transparency and written terms — we give you both. We do not offer a Canadian hosting region today; tell us if that matters to your lodge.

Can foreign authorities access our data because it's in the US?

Data stored in the United States may be accessible to US courts, law enforcement, and national-security authorities under US law. We disclose this plainly rather than leaving it implied — see our Privacy Policy.

Do you have a data processing agreement (DPA)?

Our Terms and Privacy Policy set out how we process your data, who our service providers are, and what happens to your data when you leave. If your lodge requires a separately signed processing agreement, tell us and we will work through it with you.

Found a security issue?

Email support@outfttr.com with details. We read every report personally and will follow up directly.

Email support@outfttr.com