Trust

Trust & Security

This page is maintained by SplashIQ to answer common security and privacy questions about the product. It describes current practices and is not an independent certification.

Authentication & access

SplashIQ uses managed authentication with email/password and Google sign-in. Sessions are protected with short-lived tokens, and every workspace is isolated by role-based access controls (owner, office, technician, homeowner). Staff and homeowner portals can be toggled independently by an owner.

Data isolation

All customer, property, visit, billing, and team data is scoped to your workspace using database row-level security. Users can only read or modify rows that belong to their workspace and role. Homeowner portal links use unguessable per-property tokens.

Encryption

Data is encrypted in transit (TLS) between your browser, our application, and our infrastructure providers, and encrypted at rest by our managed database and storage providers.

Hosting & subprocessors

SplashIQ runs on the Lovable platform with Supabase (Postgres, Auth, Storage) as the managed backend. Email delivery and outbound notifications use vetted providers under data-processing agreements. We do not sell personal information.

Payments & integrations

Optional integrations (QuickBooks, Klarna financing requests, marketing email) are opt-in per workspace. Credentials for connected services are stored server-side and never exposed to browsers.

Data retention & deletion

Workspace owners can export or delete records from inside the app. Account deletion requests are honored within 30 days. Contact hello@splashiq.ai to request a full export or erasure.

Vulnerability reporting

If you believe you have found a security issue, please email hello@splashiq.ai. We appreciate responsible disclosure and will acknowledge reports promptly.

Shared responsibility

SplashIQ provides the platform controls described above. Workspace owners are responsible for managing teammate access, using strong passwords, enabling two-factor authentication where available, and configuring integrations appropriately for their business.

For privacy details, see our Privacy Policy and Terms of Service.