Security
Your customers’ data, handled properly.
A sauna holds names, phone numbers, visit history and occasionally a health note. That is real personal data and it deserves better than a vague trust page. Here is what actually protects it.
EU hosting
- Application and database hosted within the European Union.
- No routine transfer of personal data outside the EEA.
- Sub-processors named publicly, with their locations.
Separation between saunas
- Every record carries the organisation that owns it.
- Isolation enforced by row level security in the database, not only in application code.
- The runtime role cannot bypass those policies.
Encryption
- TLS on every connection, HTTPS only, HSTS enabled.
- Data encrypted at rest by the hosting platform.
- Card details never touch our servers.
Access
- Staff accounts scoped by role. Owners see billing and reporting, staff do not.
- Our own access to customer environments is limited to support and is logged.
- Credentials held in a managed secret store, never in the codebase.
Resilience
- Automated backups with point in time recovery.
- Recovery point objective under one hour.
- Recovery time objective of one hour.
Change control
- Automated tests run on every change before it can ship.
- Booking and payment paths carry the heaviest test coverage.
- Changes are deployed from version control, never by hand on a server.
Being straight about it
What we do not claim.
Security pages tend to imply certifications nobody has. Ours does not.
- We do not hold ISO 27001 or a SOC 2 report. If a certification is a hard requirement for you, say so early and we will tell you honestly where we are.
- We have not had an independent penetration test published. When we do, it will be named on this page with a date.
- Firespark is a cloud product. If your connection is down, the console at your counter is down with it. Online bookings keep working because they never touched your building.
Reporting a problem
Found something? Tell us.
Email security@firespark.ie with what you found and how to reproduce it. We acknowledge within two working days and we will not come after anyone acting in good faith.
Please do not
Run automated scanners against production, access or alter data that is not yours, or disclose an issue publicly before we have had a reasonable chance to fix it.
Related: data processing agreement, sub-processors and service levels.
See it running against your own schedule.
Thirty minutes, screen shared, your prices and your sessions loaded in. If it is not a fit we will say so.