Security
Security and your data
You are trusting us with your customer list, your bookings and your students' medical answers. This page says plainly how that is looked after — and where something is still being finished, it says that too.
Your business is walled off from every other one
Each business's data is separated inside the database itself, not just by the app. If the app ever asked for the wrong business's records, the database would return nothing rather than the wrong rows. That separation is tested automatically, including what happens when something goes wrong.
Card numbers never reach us
Card details go straight to the payment processor, Stripe. Side Quest Booking never sees or stores a card number, so there is none here to lose.
Medical answers are kept apart
- Crew see whether a student is cleared, never the answers themselves.
- A yes on a medical question holds the student until someone records a doctor's sign-off, and who cleared them is recorded.
- You choose, question by question, which answers count as medical.
Who on your team can see what
Owner, manager and crew are real roles. Crew see the roster they need for the day and nothing about money or medical history. Only the owner can change where the money goes.
Two-step sign-in (a code from an app on your phone) is available to everyone, and an owner can require it for their whole team. Anything that moves money — a refund, charging a card, connecting payments — asks for the code again if it has not been entered in the last ten minutes.
When Side Quest Booking support needs to look
Nobody at Side Quest Booking can open your customers' details without your say-so.
- Support asks, and only the owner decides. Nobody at Side Quest Booking can approve their own request.
- Access comes in three levels — settings only, bookings, and medical — and each has to be granted separately.
- It expires on its own: four hours for settings, two for bookings, one for medical. Revoking it ends a visit in progress, not just the next one.
- While support is in, every screen of your dashboard shows a banner saying so.
- Everything support changes is written to a log before it happens — if it cannot be logged, it does not happen. You can read that log yourself.
Signed documents cannot be changed
A signed waiver is stored exactly as it was signed and cannot be edited afterwards, by you or by us. Publishing a new version of your waiver never changes what someone already signed, and a signed waiver can be archived but never deleted.
Backups
- A full backup is taken every night, and a copy leaves the building within a day.
- Backups are encrypted before they are written. The key to open them is kept offline, not on the servers that hold them.
- Restoring from a backup has been tested end to end, not just assumed.
- A live copy of the database is also kept at a second location, a few seconds behind.
Passwords are stored hashed, never in a form anyone can read back, and the few secrets Side Quest Booking holds for you — like the link to your Google Calendar — are encrypted with keys kept apart from everything else.
Your customers are not our audience
- We do not sell, share or market to your customers.
- This site has no tracking and no analytics, so there is no cookie banner to click through.
- Customers you bring across from another system are never emailed or texted automatically about bookings made before the move.
Questions about any of this are welcome on a demo — we would rather answer them before you move than after.