Security
Last updated 2 August 2026. How Trimelo protects salon and client data across booking, payments, and messaging.
Overview
Security is part of how Trimelo is built — not a marketing add-on. Report suspected vulnerabilities or incidents to admin@trimelo.io.
Payments and PCI
Card data is collected and stored by Stripe. Trimelo never stores full card numbers. Client charges are direct charges on the salon’s Stripe connected account, which keeps Trimelo out of the client→salon funds flow and avoids client-facing platform fees by design.
Saved cards are keyed per client and connected account. A card saved with the salon is not silently reused on a different payee account.
Access and tenancy
Staff sign in via Auth0. Salon membership and roles (including ChairRenter scoping) are resolved from our database on each request — not from stale token claims — so access changes take effect without waiting for a cookie to expire.
Tenant data is salon-scoped in application queries, with Postgres row-level security as a fail-closed backstop so a missing filter cannot casually read another salon’s rows.
Encryption and hosting
Traffic is protected with TLS in transit. Data at rest is encrypted by our hosting and database providers. Application secrets and API keys are kept in environment configuration, not in client-side code.
Messaging
Outbound SMS/email is queued and drained asynchronously so a messaging outage cannot block a booking write. Commercial SMS respects STOP suppressions.
Inbound SMS and delivery-receipt webhooks are authenticated by a secret carried in the callback URL, compared in constant time; if that secret is unset the endpoints refuse every request rather than fall open. Our SMS provider does not offer signed webhooks, so the compensating controls carry the weight: the actions an inbound webhook can trigger are idempotent, and the delivery-receipt endpoint only records delivery status — it cannot change a message's state or cause anything to be sent.
AI agent boundary
The SMS AI agent does not hold direct database credentials for salon tables. It receives authorised facts over an internal API, which limits how booking data can leave the app boundary. Client CSV import planning is likewise stateless: the agent receives only headers and redacted sample rows, returns an allowlisted mapping recipe, and never writes salon data.
Operational practices
We use encryption, least-privilege service roles, audit-minded logging for sensitive actions, and dependency/platform updates as part of normal operations. No system is perfect — if you discover a security issue, please email us promptly so we can investigate.
This summary reflects how Trimelo works today. It is not a substitute for legal advice. ABN and registered entity details will be added when available.