Security
Built so one business can never see another's.
A plain account of how Sulit Suites handles provider and client data, payments and access, with nothing claimed that is not in place.
Where your data lives and who can see it
Every booking, client record, payment record and site document is scoped to the business that owns it, and that scope is enforced in the database itself with row-level security, not only in the application. One business can never read another's clients or bookings, and a client can only see their own bookings.
Sulit Suites runs on Cloudflare's edge network with a Supabase (Postgres) database shared across the Sulit ecosystem, Stripe for payments and a transactional email provider for confirmations and receipts. Those providers may process data outside Australia; the privacy policy describes this.
Payments
- Card details are entered on Stripe's hosted payment pages. Card numbers never reach Sulit Suites.
- Each provider's payments run on their own Stripe Connect account. Sulit Suites never holds client funds.
- Stripe verifies the provider's identity and bank account. Sulit Suites does not store identity documents or bank credentials.
- Webhooks from Stripe are signature-verified before anything is recorded, and every payment event is processed once, so retries cannot double-record a payment or a refund.
- Production and test payment modes are kept separate and the server refuses to run with a mismatched key.
Accounts and access
- Sign-in uses Supabase Auth with email confirmation; providers and clients share one Sulit account.
- Every server action re-checks who is calling and what their plan allows. Hiding a button never grants access.
- Platform administration has its own sign-in on a separate host, is limited to named accounts, and security-relevant actions such as suspensions and refunds are written to an audit trail.
- Client portal access is by signed-in account or by a short-lived emailed code; a booking reference alone opens nothing.
Public sites and media
- Only published mini-sites are visible, and only at their own address. Drafts and unpublished media are not served.
- Providers choose whether search engines may index their site.
- Private pages (dashboard, client portal, booking confirmations) carry a noindex directive and are not in the sitemap.
Tracking
There are no advertising trackers, no sale of data and no client lists shared between businesses. Public page views are counted on the server by referral source only, without cookies, IP addresses or identifiers, so the team can see whether people arrive from search, from an AI assistant, or directly.
Operations
- Secrets are held only in the deployment pipeline and the production Worker, never in client code or the repository.
- Every change is tested, type-checked and built before it reaches production, and the previous version can be restored.
- Database changes are forward-only migrations, reviewed before they are applied.
Security questions
- Does Sulit Suites see my clients' card numbers?
- No. Cards are entered on Stripe's hosted pages and never reach Sulit Suites.
- Can another business on Sulit Suites see my clients?
- No. Client records are scoped to your business in the database itself.
- Can I delete my data?
- Yes. Providers can ask for their account data to be exported or deleted, and clients can ask the business they booked with to correct or delete their details. Requests are answered within 30 days. See the privacy policy.
- How do I report a site that breaks the rules?
- Email hello@sulit.today with the address and what you saw, as described on the Help page. Reports are reviewed by a person.
Start free. Upgrade when it is worth it.
Free is a real plan, not a trial. Set up your services, availability and mini-site in minutes, then share one link.
