Data Security

Last updated: 2026-08-16

We treat the security of your data as a first-order concern. This page summarises the main measures we take to protect it.

1. Encryption

All traffic between your browser and the service is encrypted in transit using TLS. Sensitive credentials β€” such as the access tokens for your connected accounts β€” are encrypted before they are stored.

2. Tenant isolation

The platform is multi-tenant by design. Every record is scoped to the organisation that owns it, and access rules are enforced at the database level so that one organisation can never read or modify another organisation's data β€” not through the application, and not through any shared query path.

3. Access control

Access to your data within your organisation is limited to the members you invite. Internally, access to production systems is restricted to the minimum number of people required to operate the service, and is logged.

4. Least-privilege connections

When you connect an external system, we request only the permissions needed for the features you use, and we act on your live accounts only through the explicit approval gate described in our Terms.

5. Data minimisation

We prefer to work with aggregated figures rather than storing individual customers' personal details, and we read only the data required for the features you have enabled.

6. Reporting a concern

If you believe you have found a security issue, please contact us immediately at support@promoosh.com so we can investigate and respond.