SuddenlySorted
Pricing How it works Book a demo Sign in
Trust & security

Your data, looked after properly

You’re trusting us with your bookings and your customers’ details. If you’re cautious about who holds that information — good, you should be. This is the honest, jargon-free account of how we keep it safe, private, and yours — not a black box you have to take on faith.

No jargon required. About a 4-minute read.

01The short version

If you read nothing else, these are the four promises behind how we handle your data.

A

Encrypted, on trusted infrastructure

Your data lives on Cloudflare’s network — the same infrastructure behind a huge share of the world’s busiest sites — and travels over encrypted (HTTPS) links.

B

Every business is walled off

Each business’s data is sealed in its own space. One business can never reach another’s — it’s built into how every request works.

C

We never see card numbers

Payments go straight to Stripe. We don’t store your card number, we don’t see it, and it never touches our database.

D

NZ-built, your data is yours

We’re a New Zealand business, we follow the NZ Privacy Act, and we’ll never sell your data. You can export or delete it any time.

02Where your data lives

The foundation everything else sits on.

Suddenly Sorted runs on Cloudflare’s global edge network — the same infrastructure that protects a large share of the world’s busiest websites. Your bookings, customer details and settings are stored in Cloudflare D1, a managed database that sits behind that network.

Every connection travels over an encrypted (HTTPS) link, so information moving between a customer’s phone, your dashboard and our servers can’t be read in transit.

In plain terms Your salon’s information is held on serious, well-defended infrastructure and scrambled while it travels — not sitting on a laptop under someone’s desk.

03Every business is walled off from every other

The single most important protection — and the one that stops anyone peeking at someone else’s salon.

When you sign in, we hand your browser a signed token that quietly says “this is your business.” From that moment on, every single thing the system fetches — a booking, a customer, a setting — is filtered by your business identity, taken from that signed token.

Crucially, that identity comes from the signed token and never from anything the browser asks for. So there’s no “change the number in the web address and peek at someone else’s salon” — the request simply can’t reach data that isn’t yours.

Checked, not assumed Our most recent internal security review specifically tested this and found no way for one business to reach another’s data. It’s also covered by automated tests that run on every release.

04We never see your card numbers

The most sensitive part of payments is handled by specialists, not us.

When you pay for a plan, your card details go straight to Stripe — one of the world’s most trusted payment companies — and are handled entirely on their secure systems. We don’t store your card number, we don’t see it, and it never touches our database.

That means the part of payments that matters most is looked after by a company whose entire job is keeping card data safe.

05The AI, and the short list of who else touches your data

No hidden hands — here’s everyone in the loop.

Sally’s replies are generated by Anthropic’s Claude, a leading AI provider. When a customer chats, the messages in that conversation are sent to Anthropic to write the reply, then come straight back. Anthropic does not use your data to train its models, and we never sell it.

Beyond that, a short, named list of trusted providers helps run the service — each doing one job, nothing more:

In plain terms Five well-known providers, each doing one job. The AI writes the replies but doesn’t keep or learn from your data. If this list ever changes, we update this page.

06A sign-in built to resist break-in attempts

Specific, enforced protections — not vibes.

07How we keep it that way

Where “we built it carefully” stops being a slogan and becomes something we can show you.

708
automated checks run on every change
89
real booking scenarios tested against the live system
0
critical or high issues in our latest review

Before any change goes live, it has to pass our automated test suite — the same checks every time, so a careless mistake gets caught before it ever reaches you. We also run a thorough internal security review of our own code. The most recent one found the system well-defended with no critical or high-severity issues, and we tightened a few things further off the back of it. We keep doing this as the product grows.

08Your privacy, your control

It’s your data. We just look after it.

We’re a New Zealand business and we handle personal information in line with the NZ Privacy Act. The data we hold is there to run your bookings and help you serve your customers — nothing more.

We keep your bookings and customer details for as long as you’re a customer, so your history and reminders keep working; chat transcripts are kept so Sally can do her job and you can review conversations. You’re in control:

If a serious data breach ever happened, we’d tell you promptly and follow the NZ Privacy Act. The full detail of what we collect and why lives in our privacy policy.

Read our Privacy Policy

Being straight with you

Trust is built on what we’re honest about, not just what we’re proud of.

What we promise

  • We’re a small, deliberate NZ team — we’d rather build fewer things and look after your data carefully than move fast and break trust.
  • We will never sell your data, or your customers’ data, to anyone. That’s not our business and never will be.
  • If you ever have a security question, a real person reads it and replies.

What we’re not (yet)

  • We’re not yet certified to a formal standard like SOC 2 or ISO 27001 — those are big-company processes. We’re honest about that.
  • The security work on this page is real and ongoing — not a badge we bought. We’d rather show you how it works than wave a certificate.