Security

How we look after your information.

Hosts trust WelcomeFlo with property details, Wi-Fi credentials, guest information and payment details. This page explains how that information is protected, which providers are involved, and where our current limits are.

At a glance

HTTPS everywhere

Every page and every published guide is served over HTTPS.

Encrypted at rest

Stored data is encrypted at rest by our infrastructure providers.

Database-level access control

Row-level security enforces who can see what, in the database itself.

Secure authentication

Handled by Supabase Auth. WelcomeFlo never sees your password.

Stripe-managed payments

Card details go straight to Stripe, never through WelcomeFlo servers.

Automated backups

Our database provider takes automated backups of production data.

Where your data lives

The WelcomeFlo application runs on Vercel. Accounts, guides and uploaded files are stored in a managed PostgreSQL database and object storage provided by Supabase, running on Amazon Web Services infrastructure in the United States.

WelcomeFlo is an Australian company, so it is worth being explicit that the data itself is hosted in the US rather than in Australia.

Encryption

Every request to WelcomeFlo, including every published guest guide, is served over HTTPS.

Data stored in our database and file storage is encrypted at rest by our infrastructure providers.

Accounts and authentication

Authentication is handled by Supabase Auth. Passwords are hashed by the authentication provider; WelcomeFlo never stores or has access to your password in readable form, and cannot retrieve it for you.

Password reset and email verification links are single-use and time-limited.

Access controls and data isolation

Row-level security is enabled on the tables that store guide, account and guest-related data, and access rules are enforced in the database itself rather than only in the application. In practice this means a request for another account’s guide, media or billing record returns nothing, even if the application layer were bypassed.

Internal analytics and administration tools are restricted to named administrator accounts. That restriction is enforced by the database on every request, not by hiding links in the interface, and administrator status cannot be granted by the account holder.

Guest guide analytics

Guest guides are public links, and guests never create an account, install an app or enter a password to read one. We record anonymous usage of a guide so hosts can see how it is being used: a randomly generated visitor identifier, a coarse device category such as mobile or desktop, a broad referrer category, and country-level location added from network information at request time.

This deliberately excludes names, email addresses and IP addresses. A host cannot use guide analytics to identify which specific guest did what.

Optional analytics on our marketing site only run if a visitor accepts them, and can be changed at any time from the Cookie Settings link in the footer.

Guest-provided information

This is different from anonymous guide analytics. Some optional features ask a guest to provide information on purpose. When a guest requests or books an Extra, such as a late checkout or an airport transfer, they provide their name, email address, phone number and the relevant dates — the details needed to fulfil that request. That information is used to deliver the Extra and is not added to any WelcomeFlo marketing list.

AI and automated features

Features such as Ask Flo, Flo Assistant, Flo Places and Flo Translations, along with listing and document import, are powered by Google Gemini. Using one of these features can send relevant content to Gemini to generate a response — for example, a guide section you ask Flo Assistant to improve, a question a guest asks Ask Flo, or content extracted from an imported listing or document.

We have not independently audited or published a position on Google’s data-retention or model-training terms for this use, so we are not making a claim about it here. If that matters for how you use WelcomeFlo, please contact us before relying on an AI feature for especially sensitive content.

When a host imports a guide from a listing URL, WelcomeFlo uses data-extraction providers to retrieve the publicly available listing information — see Service providers below.

Payments

Card payments — for a WelcomeFlo subscription, and for a guest paying for an Extra — are processed by Stripe. Card numbers are entered directly with Stripe and are never sent to or stored on WelcomeFlo servers. For subscriptions, we store a customer reference, the subscription status, and the last four digits and card brand shown to you in billing settings.

Guest Extras payments go through each host’s own connected Stripe account, so funds go directly to the host. Refunds are issued through Stripe and are debited from that same connected account.

Backups and recovery

Our managed database provider takes automated backups of the production database. We have not yet published a formal recovery time or recovery point objective, and we would rather say so than imply a guarantee we have not tested.

Service providers

WelcomeFlo relies on a small number of providers, each of which may process some data on our behalf:

WelcomeFlo service providers and what each one is used for
ProviderPurpose
VercelApplication hosting and content delivery.
SupabaseDatabase, authentication and file storage, running on AWS infrastructure in the United States.
StripeSubscription billing, and guest Extras payments through each host’s own connected Stripe account.
Google GeminiThe AI model behind Ask Flo, Flo Assistant, Flo Places and Flo Translations.
Google Maps PlatformMaps and place information shown inside guest guides. A guest’s browser communicates with Google directly when a guide displays a map.
Apify and Bright DataRetrieve publicly available listing information when a host imports a guide from an Airbnb or Booking.com listing URL.
ResendTransactional email: account emails, guides shared to a guest by email, and Extras notifications.

Data deletion and retention

You can request account deletion from your account settings. Your guides come offline and your subscription is cancelled straight away. After a recovery window, your account and its data — including profile, guides, content and media — are permanently deleted.

Some records are kept after deletion, with the link to your account removed, where we need them for legal, accounting, fraud-prevention or dispute-resolution reasons — for example, payment and order records. Our Privacy Policy explains this in full.

Where we are today

WelcomeFlo is an early-stage, founder-led product, and we would rather be straightforward about the limits of that than imply otherwise.

WelcomeFlo is not SOC 2 or ISO 27001 certified. We have not commissioned an independent security audit or penetration test, and we do not currently run a bug bounty programme. If any of that changes, this page will be updated.

Reporting a security concern

If you believe you have found a security vulnerability, please contact us before disclosing it publicly, and include enough detail for us to reproduce the issue. We will acknowledge your report and keep you updated while we investigate.

We will not pursue legal action against anyone who reports a genuine vulnerability in good faith and does not access or modify other people’s data while investigating.

Questions about security, or a vulnerability to report? Get in touch.

Contact us

This page describes how WelcomeFlo works today and will be updated as the product changes. For how we handle personal information, see our Privacy Policy.

WelcomeFlo logo