Payment security
All card payments are processed through Stripe, which is PCI DSS Level 1 certified — the highest level of payment security certification. Sailia never stores, processes, or has access to full card numbers.Because Sailia does not handle card data directly, your PCI compliance scope is significantly reduced. Stripe manages all card storage and processing.
Data encryption
- All data transmitted between your browser and Sailia is encrypted using HTTPS/TLS.
- Data at rest is encrypted in Sailia’s infrastructure.
- API communications between Sailia and third-party services (Stripe, Xero, Adventuro) use encrypted connections.
Customer data
Sailia stores customer data that you and your customers provide during the booking process. This includes:- Contact information — name, email address, phone number
- Booking history — reservations, purchases, cancellations, and refunds
- Waiver responses — completed waivers including signatures and uploaded files
- Membership and pass data — active plans, billing status, and redemption history
- Family member details — names and details of family account members
Customer data controls
You have several options for managing customer data:Staff access controls
Sailia uses permission groups to control what staff members can see and do. This lets you follow the principle of least privilege — give each team member only the access they need. Key permission areas:- Schedule access — view and manage bookings
- Financial dashboard — view payment data and exports
- POS access — process in-person sales
- Communications — manage workflows and marketing
- Staff management — add and manage team members
Third-party integrations
When you connect Sailia to external services, data is shared only as needed for the integration to function:Email and communication
Sailia sends emails on your behalf for booking confirmations, refunds, waitlist notifications, and automated workflows. These emails are sent through Sailia’s email infrastructure.- Emails include your business name and branding
- Customers can unsubscribe from marketing communications
- Transactional emails (booking confirmations, refunds) cannot be unsubscribed from as they relate to active transactions
Your responsibilities
As the business using Sailia, you are responsible for:- Communicating your privacy policy to customers, including how their data is used for bookings and marketing
- Managing consent for marketing communications through your newsletter forms and booking flow
- Responding to data requests from customers who want to access, correct, or delete their personal information
- Configuring appropriate staff permissions to limit access to sensitive data
If you operate in a jurisdiction covered by data protection regulations (such as GDPR in the EU or UK), ensure your use of Sailia complies with your legal obligations. Contact Sailia support if you need assistance with a data subject request.
Reporting security concerns
If you discover a security vulnerability or suspect unauthorized access to your account:- Change your password immediately.
- Review your staff permissions for any unauthorized changes.
- Contact Sailia support with details of the concern.
Related guides
Permissions reference
Full list of staff permissions and role configurations.
Customer management
View and manage customer data and profiles.