Security
How Kilndar looks after your studio's data and your customers'. Every line below describes how the product works today.
Where it lives.
Your data sits in a Postgres database in Ireland, hosted on Supabase, which encrypts data at rest. The app runs on Vercel from Dublin. Every connection to Kilndar is encrypted over HTTPS.
Kept separate.
Every record carries the studio it belongs to, and row-level security in the database lets only that studio's own staff read or change it.
Payments.
Card payments go through Stripe, on Stripe's own checkout page or on payment fields loaded from Stripe. Card numbers never touch Kilndar's servers.
Who can see what.
Staff sign in with their own account as owner, manager or host, and can be limited to their own branch. On a shared counter tablet, enrolled once by a manager, staff switch with a personal PIN. Customers have no account to break into: each booking link is signed and opens that booking only.
A record of changes.
Changes to bookings, sessions and activities, including the ones confirmed in the AI console, are written to an audit log with who made them and what changed.
Your data.
Reports, the front desk list, course rosters and the collections board download as CSV. A customer's profile and full booking history download in one click, and a customer can be anonymised on request.
GDPR.
For your customers' data, we act as your data processor. The companies we rely on are listed on our Sub-processors page.
Questions.
Email hello@kilndar.com.