Trust & Security
Built to protect your data.
Slot'd handles bookings, client records, and payments for independent businesses. Here's how we keep that information safe — in plain language.
Payments
Card data goes straight to Stripe
All payments run through Stripe, a PCI-certified payment provider. Card details are entered directly into Stripe and never touch Slot'd servers— we don't see, store, or transmit full card numbers. When a client pays online, funds settle to the provider's own connected Stripe account.
Infrastructure
Encrypted, on Google's cloud
Slot'd runs on Google Firebase — the same infrastructure that powers apps at global scale. Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by Google Cloud. Our sites are served over HTTPS only, with HSTS enabled.
Data handling
Your data, kept to itself.
Each business is isolated
Every provider's clients, notes, and schedule live in their own space. One business can never read another business's data, and we don't sell, rent, or trade personal information.
No tracking while clients book
When a client is booking, paying, or managing an appointment, Slot'd runs no advertising pixels and no third-party analytics. Those pages do no cross-site tracking.
Sign in securely
Provider accounts are protected by Firebase Authentication, with email-and-password or Google and Facebook sign-in. We never see your Google or Facebook password.
Export or delete your data
Providers can export their client list at any time and can permanently delete their account and its data from the dashboard. See the Privacy Policy for the full detail on your rights.
Sub-processors
Who helps us run Slot'd.
We rely on a small set of vetted infrastructure partners. They process data on our behalf under their own security commitments.
Report a vulnerability
Found a security issue?
We appreciate responsible disclosure. If you believe you've found a security vulnerability, please email us with the details and we'll respond as quickly as we can.
joe@lawndart.dev