Legal
Security
How HauzHost protects your data.
Effective June 29, 2026 · Last updated June 29, 2026 · Version 2026-06-29
Security is core to how we build HauzHost. This overview summarizes our practices; it is not a guarantee, as no system is perfectly secure.
In transit & at rest
- All traffic is served over HTTPS/TLS. Sessions use signed, HTTP-only cookies.
- Sensitive uploads (e.g. identity documents) are kept in access-controlled storage and exposed only to the host and tenant they belong to.
Access & authentication
- Passwords are stored only as salted hashes; we never store them in plain text.
- Accounts support multi-factor authentication (passkeys / security keys).
- Data is scoped per organization, so one host’s data is isolated from another’s.
Payments
Card and bank details are handled by Stripe, a PCI-DSS Level 1 provider. We do not receive or store full payment-instrument numbers.
Operations
- Infrastructure and DNS run behind Cloudflare. Server logs are retained no more than ninety days.
- We take regular database backups to support recovery.
Reporting an issue
If you believe you’ve found a vulnerability, please contact privacy@hauzhost.com. We will acknowledge and investigate responsibly and will notify affected users of a qualifying breach as required by applicable law.