Your customer data, handled carefully.
This page is maintained by the FloorOS team to answer the security and privacy questions retailers ask most. We list only the controls we actually run — not aspirational claims or certifications we don't hold.
All traffic uses TLS 1.2+. Data at rest is encrypted with AES-256 on managed Postgres and object storage.
Every row in every table is scoped by tenant with Postgres row-level security. Portal links are single-purpose signed tokens.
Application and database run in EU regions. Customer data is never copied out of the EU by FloorOS.
Email + password with breach-list checks, plus SSO (Google). Sessions rotate on password change and sign-out.
Automated daily backups with 30-day point-in-time recovery on the managed database.
Role-based permissions (owner, manager, sales, fitter, viewer). Portal access is scoped per document via short-lived tokens.
GDPR & data protection
FloorOS acts as a data processor for the personal data you upload about your customers and staff. You are the controller and retain full control: export your data at any time from Settings → Export, and request deletion from Settings → Danger zone. A signed Data Processing Addendum is available on request — see our DPA, Privacy policy and Terms.
Subprocessors
We use a small set of trusted providers to run the service. All are GDPR-compliant and bound by data processing agreements.
| Provider | Purpose | Region |
|---|---|---|
| Managed Postgres & Auth | Application database, authentication, storage | EU (Frankfurt) |
| Cloudflare | CDN, WAF, DNS | Global edge |
| Resend / SES | Transactional email delivery | EU |
Found something? Email security@flooros.co.uk. We respond within 2 working days and credit responsible reporters where appropriate.
Ready to see it on your own data?
14-day trial. No card required. Free migration. Cancel from Settings in one click.