Platform Solutions Property Managers The Blueprint Customers Pricing Resources Contact Sign in
Home / Security
Trust & Security

Your clients trust you with the keys.
Here's how we protect them.

The property managers and owners you clean for hand your company door codes, guest stays, and a live connection to their booking system. When they ask how that's protected, send them this page. It says what Rinsebase does — and what it doesn't do yet.

The real risk

Most cleaning companies' security is a group text.

Lockbox codes pasted into a thread that everyone who has ever been added can scroll back through. A client's booking-system login saved in the owner's notes app. A spreadsheet of access instructions forwarded every Friday.

None of that has a lock on it. And it's exactly what a property manager is picturing when they ask a new cleaning partner, "where does our guest information actually go?"

Rinsebase moves it into one system with sign-in, roles, and rules the database enforces — so the answer is a page you can send, not a promise.

Crew — Weekend Turnovers
OwnerLockbox for the Harbor St unit is 2-9-1-4. Gate is the same.
CrewDoes anyone have the login for the Guesty calendar??
YouCheck the pinned msg from March
OwnerNew crew member starts Saturday — adding them to this chat 👋
Illustration — the status quo, not Rinsebase
How it's protected

Rules that hold no matter who's asking.

An app that hides a button isn't security. These protections live where the data lives, so they apply to every screen, every phone, and every request.

Enforced in the database
Every company is walled off
Row-level security runs on every table that holds customer data. Your clients, properties, crew and invoices are only ever returned to your company — never to another cleaning company on the platform.
Enforced in the database
Each portal sees only its own client
Client and property-manager portal links are checked in the database against the link that was issued. A portal shows that client's properties, cleans and photos — and nothing belonging to anyone else you clean for.
Enforced in the database
Crew get the job, not the business
Crew can clock in, upload photos, work checklists and report supplies. They can't change your prices, invoices, payments, client records, company settings or calendar connections — the database rejects it from a crew account.
Enforced on the server
Every request proves who's asking
Backend functions that invoice, notify, invite or sync check who's calling — and which company they belong to — before they touch a single record. Having an ID isn't enough to act on it.
Built into the connect flow
You never touch your client's login
Your client connects OwnerRez, Hospitable, Guesty or Hostaway from their own invite link and picks which listings you clean. Nobody at your company types in their password or API key — and once it's connected, nobody at your company can read it back, owners included.
Processed by Stripe
Card numbers never reach Rinsebase
Client payments run through Stripe and land in your own Stripe account. Rinsebase keeps the card brand and last four digits for the invoice — never the card number.
Infrastructure & your data

The details a procurement team asks for.

The formal terms live in our Data Processing Agreement. Here's the short version.

Hosting
Database, sign-in and file storage on Supabase — SOC 2 Type II audited infrastructure in US data centers. The web app is served by Vercel.
Encryption
TLS 1.2 or higher for everything in transit. Data is encrypted at rest.
Passwords
Handled by Supabase Auth and stored as bcrypt hashes, never in plain text.
Backups
Daily database backups.
Who owns the data
Your company. You're the data controller; Rinsebase processes it only to run the service. We don't sell it, and we don't use it to train AI models.
If something goes wrong
We notify you without undue delay — within 72 hours where feasible — with what happened, what was affected and what we're doing about it.
If you leave
Your data stays accessible for 30 days after cancellation, then is scheduled for permanent deletion. Request a full export any time before then.
Paperwork
Our Data Processing Agreement applies to every customer automatically. Need one countersigned for a client contract? Email admin@rinsebase.com.
Straight answers

What we don't have yet.

A security page that only lists strengths isn't much use to someone signing a contract. If either of these is a requirement for your client, find out before you sign — not after.

Rinsebase isn't SOC 2 audited as a company
The infrastructure we run on is SOC 2 Type II audited; Rinsebase itself hasn't been through an audit. When a client's procurement team sends a security questionnaire, we complete it in writing.
No two-factor sign-in or SSO
Sign-in is email and password today. Two-factor authentication and SAML single sign-on aren't available yet. If a client contract requires them, tell us before you sign it.

Your client sent a security questionnaire?

Forward it. We'll fill it out in writing, so you can answer the property manager with specifics instead of reassurance — and get back to winning the account.

Common questions

Security FAQ

Is Rinsebase SOC 2 certified? +
Not as a company, yet. Rinsebase runs on Supabase, whose infrastructure is SOC 2 Type II audited, and our Data Processing Agreement covers every customer. If your client's procurement team sends a security questionnaire, we'll complete it in writing.
Can another cleaning company see our data? +
No. Every table that holds customer data enforces row-level security in the database, so your records are only returned to your company's signed-in users and to the client portals you've issued. The rule lives in the database, not the app, so it holds no matter how the data is requested.
What can our crew change? +
Crew can do the job: clock in, upload photos, work checklists and report supplies. They can't change your prices, invoices, payments, client records, company settings or calendar connections — the database rejects those changes from crew accounts.
Do we ever handle our client's booking-system login? +
No. Your client connects their own booking system from an invite link and picks which listings you clean. OwnerRez and Hospitable connect with a one-click approval; Guesty and Hostaway connect with an API key your client generates and pastes on their side. Nobody at your company types in their password or key.
Is our data used to train AI? +
No. Rinsebase does not use your company's, your clients' or your crew's data to train machine-learning or AI models. That commitment is written into our Data Processing Agreement.
What happens to our data if we cancel? +
It stays accessible for 30 days after cancellation, then it's scheduled for permanent deletion. You can request a full export any time before then at admin@rinsebase.com. Some billing records may be kept longer where the law requires it.
How do we report a security issue? +
Email admin@rinsebase.com with what you found and how to reproduce it. We'll acknowledge it and tell you what we're doing about it. Please don't access, change or delete data that isn't yours while testing.

Last reviewed September 14, 2026