Real answers, not a compliance-theater checklist. Here's what we actually do to keep your lodge's data safe.
Everything moves over HTTPS. Your database is encrypted at rest, and sensitive tokens (like third-party account connections) get a second layer of encryption at the application level.
Isolation is enforced at the database engine itself, not just in application code. No customer can query another customer's data. Platform staff access data only for support and troubleshooting.
Every team member gets only the access their role needs — Owner, Manager, Staff, or Guide. Every change to a booking, charge, or guest record is logged with who made it, when, and what changed.
A backup runs automatically every day and is encrypted before it's stored. Every run restores the data from that backup into a separate test database and checks each table's rows against the snapshot it was made from. If anything doesn't match, we're alerted.
Card numbers are handled directly by our payment processor. Outfttr never holds your money and never sees or stores full card details.
Errors, failed background jobs, and service problems are caught automatically and routed to an alert — not discovered because a guest called in to complain.
Login, signup, and other public forms are protected against automated abuse, so a scripted attack can't hammer them.
Full data export — guests, reservations, charges, and reports — available any time from Settings. Leave whenever you want. No penalty, no waiting on us.
Your data is hosted in the United States. We tell you and your guests that in writing rather than leaving it implied. The full list of service providers we use to run Outfttr, and where each one operates, is in our Privacy Policy.
There's no such certification — PIPEDA obligations belong to your lodge, not to us. We built Outfttr to support your PIPEDA obligations: encryption, access controls, an audit trail, and clear written terms on how we process your data.
On servers located in the United States. Canadian privacy law allows this with transparency and written terms — we give you both. We do not offer a Canadian hosting region today; tell us if that matters to your lodge.
Data stored in the United States may be accessible to US courts, law enforcement, and national-security authorities under US law. We disclose this plainly rather than leaving it implied — see our Privacy Policy.
Our Terms and Privacy Policy set out how we process your data, who our service providers are, and what happens to your data when you leave. If your lodge requires a separately signed processing agreement, tell us and we will work through it with you.
Email support@outfttr.com with details. We read every report personally and will follow up directly.
Email support@outfttr.com