Security & your data
HappierBiz looks after the things that matter most to your business, your customer list, your bookings, your takings and your team's details. This page explains, in plain English, how we protect them, and the few simple things you can do to stay safe. Everything described here is switched on and working today.
In one line: your data is encrypted, walled off from every other business, reachable only by the right people, and your customers' card details never touch our systems.
๐ Download the full Security Guide (PDF), a customer-friendly overview you can share with your team or clients.
How we protect you
| Protection | What it means for you |
|---|---|
| Encryption | Everything travels over a secure (HTTPS) connection and is encrypted when stored. Your accounting (Xero) keys get an extra layer of AES-256 encryption. |
| Per-business isolation | Your data is separated from every other business at the database level, not just hidden on screen. No other customer can ever see your records. |
| Two-factor sign-in (2FA) | An optional second check (a code from your phone) so a stolen password isn't enough to get in. Owners can require it for the whole team. |
| Role-based access | Each person sees only what their role allows. Limits are enforced on our servers, so they can't be bypassed with a browser trick. |
| Private file storage | Documents and form attachments are kept in a private store and opened through short-lived, role-checked links, never a public web address. |
| Audit trail | Sensitive actions (price changes, voided invoices, security settings) are written to a tamper-proof log: who did what, and when. |
| Australian hosting | Your data is stored and served from Australian data centres. |
Behind the scenes we also apply secure browser protections and defences against the common web attacks, and we keep secret keys server-side so they never reach your browser.
Payments are handled by Stripe
When customers pay you, their card details are entered on Stripe's secure systems, never ours. HappierBiz never sees or stores a full card number. Stripe is certified to the highest card-security standard (PCI-DSS Level 1), the same processor used by businesses worldwide. Every payment confirmation Stripe sends us is digitally signed and checked, so fake "you've been paid" messages are rejected.
Your data, your privacy
- The built-in AI assistant is private by design, it only ever sees summaries and first names, never full customer records. (See AI, data & privacy for the full detail.)
- Marketing messages respect consent rules, with one-click unsubscribe.
- If you ever leave HappierBiz, your data is permanently removed after a short grace period.
What you should do
Security works best as a partnership. These habits take under a minute each and make the biggest difference:
- โ Turn on two-factor sign-in (Account โ Security), and require it for managers.
- โ Use a unique, long password, never reuse your email password.
- โ Give each staff member their own login, never share one account.
- โ Remove access the day someone leaves (the Team offboarding tools do this in one step).
- โ Review permissions every few months, give the least access needed.
- โ Export important records now and then as your own safety net.
- โ Be alert to scam emails, HappierBiz will never ask for your password or 2FA code.
Frequently asked
Can another business see my data? No, businesses are separated at the database level, enforced on every table.
Do you store my customers' card numbers? No, that's handled entirely by Stripe.
Is my data kept in Australia? Yes, in Australian data centres.
What if a staff member leaves? Switch off their access immediately; this also removes their future shifts and links to your business.
What if I forget my password? Use forgot password, a secure reset link is sent only to your verified email. If you've enabled 2FA, that still applies.
Where to get help: for any security question, email support@happierbiz.com.au.