Security & trust

Built to protect your money and your data

VenueFuze is a payment facilitator: funds land in your own processor, card data stays with your PCI-compliant provider, and the sensitive things we do store are encrypted. Here's exactly how it works.

Payments & card data

VenueFuze never sees or stores full card numbers. Checkout runs on your own PCI-compliant processor's hosted page.

  • Card details are entered on Stripe, PayPal, or Square's own hosted checkout — not on a VenueFuze form.
  • We store only a payment reference (a token/ID), never the card number, CVV, or full PAN.
  • Your processor carries the PCI-DSS obligation for card handling; VenueFuze stays out of that scope by design.

Your money

VenueFuze is a payment facilitator, not a wallet. Funds settle directly to the account you connect.

  • Every sale is paid into your own Stripe, PayPal, or Square account — we never hold or pool your funds.
  • No payout holds and no platform balance to withdraw. You control your own payout schedule with your processor.
  • We bill our ~3% share to your organization after the event, so there's nothing to reconcile against a platform wallet.

Encryption

Sensitive values are encrypted at rest, and everything travels over TLS.

  • Stored processor secrets and integration tokens are encrypted at rest with AES-256-GCM.
  • All traffic is served over HTTPS/TLS with HSTS enabled.
  • QR tickets are signed with an HMAC so a ticket can't be forged or reused.

Access & tenancy

Each organization's data is isolated, and every action is authorized by role.

  • Role-based access (Owner, Admin, Staff, Front-desk) governs who can do what.
  • Data is scoped per organization — one customer can't read or write another's records.
  • Sensitive server actions re-check the caller's permission on every request, not just when a page loads.

Backups & recovery

Your data is backed up on a schedule and replicated off-site.

  • The database is backed up nightly, with off-site replication to separate cloud storage.
  • Backups let us recover from hardware failure or accidental data loss.

Privacy & compliance

We collect only what's needed to run your events, and we document how we handle it.

  • See our Privacy Policy for what we collect and why, and our Data Processing Addendum (DPA) for processor terms.
  • Personal data is never placed in URLs, and we default to the most privacy-preserving choices.

Responsible disclosure

Found a security issue? We want to hear about it. Email security@zafronix.com with the details and steps to reproduce, and we'll respond. Please give us a reasonable window to fix an issue before disclosing it publicly.

Privacy Policy · Data Processing Addendum · Terms of Service