Security
Last change: 5 October 2026
How we protect your account, your data and your payments.
Contents
1.Payments
Ticket payments run through Stripe, certified to PCI DSS Level 1, the highest level for card payments. Card details go straight to Stripe. We never see or store your full card number.
2.Accounts
- You sign in with a one time code sent to your email, so there is no password to leak or reuse.
- Sign in is handled by Clerk, a dedicated authentication provider. Sessions expire and are checked on every request.
- Every request is tied to your verified email: you can register only yourself, not someone else's address.
- In the iOS app your session is kept in the iOS Keychain.
3.Privacy
We do not sell your data and show no ads. Hosts see only the guests of their own events, and other guests see counts, not names. More in our Privacy Policy.
4.Infrastructure
The Service is hosted on Amazon Web Services in the United States, with files on Supabase. AWS data centers hold certifications including ISO 27001 and SOC 1, 2 and 3. Backups are made with cloud native tools and checked regularly, so data can be restored after an incident.
5.Encryption
- In transit: every connection uses HTTPS (TLS).
- At rest: data is encrypted on our infrastructure.
- Credentials and tokens are hashed or encrypted, never stored in plain text.
- Profile photos are stored under unguessable addresses.
6.Access control
- Staff get access only when their role needs it, and lose it when it no longer does.
- Production systems are limited to authorized technical staff, through encrypted authentication.
- Every change made through our API is logged with who made it, what and when.
- Data of each host organization is kept logically separate.
- Everyone with access is bound to confidentiality and trained on data protection.
7.Development
- Changes are reviewed and tested before they reach production.
- Automated tests check that private data stays private, such as who can read a guest list.
- Links to other sites are fetched only over HTTPS and only from public addresses, so they cannot reach our internal systems.
- We follow established secure development practices.
8.Incident response
We monitor our systems and follow a written incident response plan. If a breach affects your data, we tell you and the authorities as the law requires, and we notify hosts whose event data is affected within 48 hours.
9.Compliance
We follow the GDPR, the UK GDPR, the Swiss FADP and California privacy law. Transfers out of Europe use the Standard Contractual Clauses. Hosts on the Pavoot platform are covered by our Data Processing Agreement.
10.Report a problem
Found a vulnerability or something that looks wrong? Email hello@pavoot.com with the details and steps to reproduce. Please give us time to fix it before telling others, and do not access data that is not yours. We reply and will credit you if you wish.