Security

Last updated: July 2026

We take the security of your business data and your customers' information seriously. This page describes the measures we have in place to keep your data safe.

Data encryption

All data is encrypted in transit using TLS 1.2 or higher. Data at rest, including your database, backups, and uploaded files, is encrypted using AES-256 by our infrastructure providers.

Access controls

FullClass uses role-based access control that the business owner configures, so you decide exactly who on your team can reach what. Permissions span around twenty distinct areas — bookings, customers, reports, staff scheduling, and more — and the owner can also gate sensitive data fields, such as customer contact details, separately from the pages that contain them.

These are starting points, not fixed presets. The owner grants or revokes any area per role, and can override access for an individual user, so each person sees only what their job requires.

Two-factor authentication

All admin accounts support two-factor authentication (2FA) using any standard authenticator app, including Google Authenticator, Authy, and 1Password. We strongly recommend enabling 2FA on all owner and admin accounts. It can be set up from your profile settings at any time.

Passwords

Passwords are hashed using bcrypt before storage. We never keep them in plaintext. After five failed login attempts, accounts are temporarily locked to prevent brute-force attacks. Password reset links expire after 24 hours and can only be used once.

Passwordless & passkeys

Staff, admin, and superadmin accounts can sign in with a WebAuthn passkey instead of a password. A passkey is bound to your device and unlocked with your fingerprint, face, or device PIN, so it is inherently multi-factor and resistant to phishing. Each account can register and manage several passkeys.

Payments

FullClass does not store payment card numbers. Customer payments are processed directly by Stripe or Square, both of which are PCI-DSS certified. We receive only a tokenised reference to completed transactions.

Your data rights

To support GDPR and similar requests, the business owner can export a single customer's data — their profile, bookings, waiver acceptances, and gift cards — as a machine-readable file, and can erase a customer's personal data on request. Both actions are restricted to the owner.

The same holds for your own account. An owner can download everything the business holds, every report as a spreadsheet, at any time, and can delete the whole account from Settings without contacting us. Deleting takes the booking page offline and cancels the subscription immediately, then permanently deletes the data 30 days later. Until that date the deletion can be undone in one click, so a misclick or a stolen login does not cost a business its records.

Backups

Your data is backed up daily to encrypted cloud storage. Backups are retained for 60 days. In the event of data loss, we target recovery of data up to 24 hours old.

Infrastructure

FullClass is hosted on Render, running in a single region in the western United States. Our infrastructure providers maintain SOC 2 Type II certification. We monitor uptime continuously. Current status is available at our status page.

Vulnerability management

Our codebase is scanned for known vulnerabilities on every code change using govulncheck. Dependencies are reviewed regularly and updated when security issues are disclosed.

Responsible disclosure

If you believe you have found a security vulnerability in FullClass, please report it to us at support@fullclass.io. We will acknowledge your report within 48 hours and work with you to understand and resolve the issue promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to address it.

Questions

If you have questions about security at FullClass, contact us at support@fullclass.io.