Trust center
Security & Trust
This page explains how WashRoute Pro protects business and customer information today. It is a factual overview, not a certification, independent audit, or guarantee.
WashRoute Pro itself does not claim a SOC 2 audit report, ISO 27001 certification, PCI certification, HIPAA compliance, a completed penetration test, or a guaranteed uptime level unless a signed agreement expressly says otherwise.
1. Who can sign in
- After someone signs in, the session expires automatically and ends when that person signs out.
- The business account, account status, and each person's role decide what that person can see and change.
- Owners, crew members, sales reps, customers using a shared link, and internal staff use separate access paths.
- When password sign-in is enabled, WashRoute Pro stores a protected password check rather than a readable password.
- Protected actions check the person's access again before saving a change.
2. Keeping each business separate
Business records are linked to one business account. Before protected information is shown or changed, WashRoute Pro checks the signed-in person, business account, and role. Billing, exports, team access, account changes, and internal tools receive additional permission checks. A customer link opens only the specific quote, photo request, report, or other item it was created for.
3. Checks around important actions
- The app sends modern security instructions to the browser to limit unsafe page behavior.
- Before important information changes, the server checks that the request came from a trusted page and that the person has permission.
- Automated request limits help protect sensitive public and sign-in pages when the live Cloudflare setup provides that protection.
- Forms and requests are checked for expected information before data is saved. Customer-facing errors are designed not to reveal secret keys or private service responses.
- Important payment and connected-service requests use repeat-request protection where a duplicate action could cause harm.
4. Shared links and file uploads
Customer-facing quote, photo, review, referral, and similar links include a private access code. Depending on the feature, a link can expire or be revoked. An invalid or unavailable link is designed not to reveal the business's private records.
For live file storage, each upload receives a short-lived permission that works only for that upload. The system tracks the business and user that own the file, its type and size, whether it is public or private, and its processing status. Safe use also depends on the live storage setup and sharing links only with the intended people.
5. Card payments
When live Stripe checkout is configured, customers enter card details on a Stripe-hosted checkout page. WashRoute Pro sends a business-specific transaction reference, and Stripe sends the payment result back to the server. The app is designed not to store full card numbers or card security codes.
6. Service keys and connected services
Private keys used for live text messaging, email, payments, and file storage stay on the server and are not sent to the browser. WashRoute Pro keeps limited status and reference information instead of secret keys or an entire private service response. Test connections are kept separate from live customer activity. If a required live service is not safely configured, the related action is shown as unavailable instead of reporting a false success.
7. Activity and permission records
WashRoute Pro can keep an activity trail for important account and business changes, customer permission records, message delivery status, connected-service references, opt-outs, requests to keep or remove records, and protected high-risk actions. These records are designed to limit how much full message text, recipient detail, secret keys, and other unnecessary private information they include.
8. What account owners should do
- Give every worker a separate sign-in, use strong passwords, and lock phones and computers used for work.
- Give each person only the access needed for that person's job.
- Change or remove access as soon as a worker changes roles or leaves.
- Check the customer and contact information before sending a quote, message, or shared link.
- Keep keys for any connected service private and replace them after suspected exposure.
- Export records the business must retain and keep a backup plan that fits the operation.
- Report suspected unauthorized access promptly.
9. Report a security issue
Choose “Private security report” on our Contact page. Tell us what you saw, where it happened, why it may matter, and a safe way to contact you. Do not view data that is not yours, interrupt the Service, trick people into sharing access, demand payment before giving us enough information to investigate, or publish an issue before it can be fixed.
We will acknowledge reports that contain enough information to investigate and prioritize them by credible customer impact. This page does not promise a bug bounty, payment, or a specific response time.
10. Scope of this statement
Security practices change as the product changes. This page describes controls in the current product as of the updated date shown on the page. It is not an independent audit, certification, warranty, service-level agreement, or promise that every optional control is active in every setup.