Security
Last updated: September 2026
Your business runs on this data, so we treat keeping it safe as part of the product, not an afterthought. Here is how we protect it in plain terms.
Your data is isolated
Every business's data is separated at the database level, so one account can never read another account's records. This isolation is enforced by the database itself, not just by the app.
Encryption
Traffic between you and Tiny Tindera is encrypted in transit over HTTPS, and data is stored on reputable managed cloud infrastructure.
Access control
- Access is permission-based: staff see only what their role allows.
- Two-factor authentication is available for accounts that want an extra layer.
- Sensitive actions can require a manager step-up, and are recorded.
Audit logs
Key actions are written to an append-only audit trail, so you can see who did what and when. Sign-ins and sign-outs are logged too.
Abuse protection
Sign-in attempts are rate-limited to slow down guessing, and platform accounts that are removed have their login revoked immediately.
Backups and availability
We run on managed infrastructure with regular backups. We work hard to keep the service available, and we post significant platform changes on our Platform changes page.
Report a vulnerability
Found something that looks wrong? We appreciate responsible disclosure. Email security@tinytindera.com with the details and we will look into it. Please give us a reasonable chance to fix an issue before sharing it publicly.
Your part
Security is a shared effort. Keep your password private, give staff only the access they need, and remove people promptly when they leave. See how we handle personal data in our Privacy Policy and Data Processing Addendum.