Skip to content

    Your data is safe. Your money is safe.

    We know you're trusting us with your business. Here's exactly how we protect your data, your customers' information, and every payment that passes through the platform.

    Your data

    How we store and protect your business information.

    Encrypted at rest

    Your data is scrambled when stored — even if someone broke into the servers, they'd see gibberish.

    AES-256 encryption at rest across all database storage.

    Encrypted in transit

    Every connection between your device and ServicePay is secured — same technology your bank uses.

    TLS 1.2+ enforced on all connections. No plaintext fallback.

    GDPR compliant

    We follow UK and EU data protection law. Your data belongs to you — export or delete it anytime.

    Full GDPR compliance including right to erasure, data portability, and breach notification.

    We never sell your data

    Your customer lists, invoices, and job details are yours. We don't sell, share, or mine them. Ever.

    Zero third-party data sharing. No analytics reselling. No AI training on your content.

    Your payments

    How ServicePay Payments keeps money moving safely. The same security posture applies whether you use ServicePay Payments or connect your own Stripe account — both are processed by Stripe, FCA-authorised, and we never see card numbers.

    Stripe handles the money

    When your customer pays an invoice, the money goes through Stripe — the same payment processor used by Amazon, Deliveroo, and thousands of UK businesses. We never see or hold your customers' card details.

    Stripe is PCI DSS Level 1 certified — the highest level of payment security. Stripe Payments UK Ltd is authorised by the FCA.

    We never hold your funds

    Payments go from your customer to Stripe, then directly to your bank account on a weekly schedule. ServicePay never sits between you and your money.

    Stripe Connect with direct charges. Funds are held by Stripe (FCA-authorised), not ServicePay, and are paid out from the business's own Stripe account on the schedule that account sets.

    Your customers are protected too

    When a customer opens a quote or pays an invoice through their portal, they use a secure, unique link — no passwords to remember or leak.

    Token-based portal access with cryptographic UUIDs. No customer credentials stored. HTTPS enforced.

    Platform security

    The less visible stuff that keeps everything locked down.

    Data isolation

    Every business on ServicePay can only see their own data. Your customers, quotes, and invoices are completely invisible to other businesses on the platform.

    Password protection

    We check every password against known data breaches. If a password has appeared in a leak anywhere on the internet, we won't let you use it.

    Admin audit trail

    Every action by our support team is logged. If we ever need to access your account to help you, there's a full audit trail of what was viewed and when.

    Regular updates

    The platform is continuously updated with security patches. We don't wait for quarterly releases — if there's a fix needed, it ships immediately.

    The short version

    • Your data is encrypted — both when it's stored and when it's moving between your device and our servers.
    • Card payments are processed by Stripe, who are authorised by the FCA. We never see card numbers.
    • Each business's data is completely isolated — no one else on the platform can see your information.
    • We follow GDPR. You can export or delete your data whenever you want.
    • We will never sell, share, or monetise your business data. Full stop.

    Got a specific question about security?