How we protect your business, your clients, and their data.
All card payments run through Stripe, a PCI-DSS Level 1 provider. Bontro never sees or stores your full card number.
Sign in with Google or email + password. Passwords are hashed with bcrypt and never stored in plain text. Mobile access tokens are short-lived and refreshed automatically.
Team members get role-based permissions (owner, manager, staff), so people only reach the parts of your business they should.
Every business's data is scoped to that business. One pro's clients, bookings, and payments are never visible to another.
Sensitive internal actions are written to an append-only audit log, so account changes are traceable.
Pros can verify their identity through Stripe Identity (government ID + selfie match).
Traffic is encrypted in transit with TLS. Data is stored on managed infrastructure (Vercel, Neon Postgres, Stripe) that encrypts data at rest.
You can delete your account from your settings. We cancel billing, remove your uploaded files, and anonymize your personal data.
Card data is handled by Stripe, which is PCI-DSS Level 1 certified. Bontro itself does not currently claim its own SOC 2, ISO 27001, PCI, or HIPAA certification, and we won't say we do until it's true. If your business has specific compliance requirements (for example, healthcare), please reach out before relying on Bontro for them.
Found a vulnerability? We appreciate responsible disclosure. Email us and we'll respond as quickly as we can.
support@bontro.co