Hosts trust WelcomeFlo with property details, Wi-Fi credentials, guest information and payment details. This page explains how that information is protected, which providers are involved, and where our current limits are.
At a glance
HTTPS everywhere
Every page and every published guide is served over HTTPS.
Encrypted at rest
Stored data is encrypted at rest by our infrastructure providers.
Database-level access control
Row-level security enforces who can see what, in the database itself.
Secure authentication
Handled by Supabase Auth. WelcomeFlo never sees your password.
Stripe-managed payments
Card details go straight to Stripe, never through WelcomeFlo servers.
Automated backups
Our database provider takes automated backups of production data.
Where your data lives
The WelcomeFlo application runs on Vercel. Accounts, guides and uploaded files are stored in a managed PostgreSQL database and object storage provided by Supabase, running on Amazon Web Services infrastructure in the United States.
WelcomeFlo is an Australian company, so it is worth being explicit that the data itself is hosted in the US rather than in Australia.
Encryption
Every request to WelcomeFlo, including every published guest guide, is served over HTTPS.
Data stored in our database and file storage is encrypted at rest by our infrastructure providers.
Accounts and authentication
Authentication is handled by Supabase Auth. Passwords are hashed by the authentication provider; WelcomeFlo never stores or has access to your password in readable form, and cannot retrieve it for you.
Password reset and email verification links are single-use and time-limited.
Access controls and data isolation
Row-level security is enabled on the tables that store guide, account and guest-related data, and access rules are enforced in the database itself rather than only in the application. In practice this means a request for another account’s guide, media or billing record returns nothing, even if the application layer were bypassed.
Internal analytics and administration tools are restricted to named administrator accounts. That restriction is enforced by the database on every request, not by hiding links in the interface, and administrator status cannot be granted by the account holder.
Guest guide analytics
Guest guides are public links, and guests never create an account, install an app or enter a password to read one. We record anonymous usage of a guide so hosts can see how it is being used: a randomly generated visitor identifier, a coarse device category such as mobile or desktop, a broad referrer category, and country-level location added from network information at request time.
This deliberately excludes names, email addresses and IP addresses. A host cannot use guide analytics to identify which specific guest did what.
Optional analytics on our marketing site only run if a visitor accepts them, and can be changed at any time from the Cookie Settings link in the footer.
Guest-provided information
This is different from anonymous guide analytics. Some optional features ask a guest to provide information on purpose. When a guest requests or books an Extra, such as a late checkout or an airport transfer, they provide their name, email address, phone number and the relevant dates — the details needed to fulfil that request. That information is used to deliver the Extra and is not added to any WelcomeFlo marketing list.
AI and automated features
Features such as Ask Flo, Flo Assistant, Flo Places and Flo Translations, along with listing and document import, are powered by Google Gemini. Using one of these features can send relevant content to Gemini to generate a response — for example, a guide section you ask Flo Assistant to improve, a question a guest asks Ask Flo, or content extracted from an imported listing or document.
We have not independently audited or published a position on Google’s data-retention or model-training terms for this use, so we are not making a claim about it here. If that matters for how you use WelcomeFlo, please contact us before relying on an AI feature for especially sensitive content.
When a host imports a guide from a listing URL, WelcomeFlo uses data-extraction providers to retrieve the publicly available listing information — see Service providers below.
Payments
Card payments — for a WelcomeFlo subscription, and for a guest paying for an Extra — are processed by Stripe. Card numbers are entered directly with Stripe and are never sent to or stored on WelcomeFlo servers. For subscriptions, we store a customer reference, the subscription status, and the last four digits and card brand shown to you in billing settings.
Guest Extras payments go through each host’s own connected Stripe account, so funds go directly to the host. Refunds are issued through Stripe and are debited from that same connected account.
Backups and recovery
Our managed database provider takes automated backups of the production database. We have not yet published a formal recovery time or recovery point objective, and we would rather say so than imply a guarantee we have not tested.
Service providers
WelcomeFlo relies on a small number of providers, each of which may process some data on our behalf:
WelcomeFlo service providers and what each one is used for
Provider
Purpose
Vercel
Application hosting and content delivery.
Supabase
Database, authentication and file storage, running on AWS infrastructure in the United States.
Stripe
Subscription billing, and guest Extras payments through each host’s own connected Stripe account.
Google Gemini
The AI model behind Ask Flo, Flo Assistant, Flo Places and Flo Translations.
Google Maps Platform
Maps and place information shown inside guest guides. A guest’s browser communicates with Google directly when a guide displays a map.
Apify and Bright Data
Retrieve publicly available listing information when a host imports a guide from an Airbnb or Booking.com listing URL.
Resend
Transactional email: account emails, guides shared to a guest by email, and Extras notifications.
Data deletion and retention
You can request account deletion from your account settings. Your guides come offline and your subscription is cancelled straight away. After a recovery window, your account and its data — including profile, guides, content and media — are permanently deleted.
Some records are kept after deletion, with the link to your account removed, where we need them for legal, accounting, fraud-prevention or dispute-resolution reasons — for example, payment and order records. Our Privacy Policy explains this in full.
Where we are today
WelcomeFlo is an early-stage, founder-led product, and we would rather be straightforward about the limits of that than imply otherwise.
WelcomeFlo is not SOC 2 or ISO 27001 certified. We have not commissioned an independent security audit or penetration test, and we do not currently run a bug bounty programme. If any of that changes, this page will be updated.
Reporting a security concern
If you believe you have found a security vulnerability, please contact us before disclosing it publicly, and include enough detail for us to reproduce the issue. We will acknowledge your report and keep you updated while we investigate.
We will not pursue legal action against anyone who reports a genuine vulnerability in good faith and does not access or modify other people’s data while investigating.
Questions about security, or a vulnerability to report? Get in touch.
This page describes how WelcomeFlo works today and will be updated as the product changes. For how we handle personal information, see our Privacy Policy.