PreOrderly.Group dining, organised.
How it worksFeaturesPricingVenuesHotelsEvent venuesResourcesSign inStart free
How it worksFeaturesPricingVenuesHotelsEvent venuesResources
Sign inStart free

SECURITY & TRUST

Protecting group-booking information.

PreOrderly is designed so venues can organise events without giving every user access to every customer's information. Security is applied at the application, database and operational layers.

Tenant and venue isolation

Customer access is scoped by organisation and venue. Database Row Level Security and automated cross-tenant tests provide an additional boundary beneath the application.

Host and guest access

Hosts and guests use purpose-specific secure booking links rather than receiving venue-user access. These links are treated as credentials and support expiry and revocation. Public booking pages are configured to avoid search indexing, shared caching and referrer leakage.

Payments

Where payment is enabled, card entry is completed using Stripe-hosted payment flows. PreOrderly does not store payment-card numbers. Payment webhooks are signature-verified before they are processed.

Privileged access and audit

Administrative and support capabilities are separated from normal venue access and sensitive support actions are recorded. Privileged database credentials are server-only and are not exposed to the browser.

Application and infrastructure security

PreOrderly uses HTTPS, browser security headers, least-privilege access controls, automated type/lint/unit/database checks and security analysis in the development pipeline. Production data and authentication services are provided through managed infrastructure with additional provider-level security controls.

Privacy and sensitive information

Allergy and dietary information is limited to the booking and food service purpose. Guests are asked not to provide unrelated medical information. PreOrderly maintains privacy, retention, data-subject-rights and personal-data incident procedures as part of its operational security programme.

Security incidents and vulnerability reporting

Suspected security or privacy issues are triaged under a documented incident process covering containment, evidence preservation, assessment, recovery and required customer or regulatory notifications. Customers should report concerns through the authenticated Support area and should never send passwords, payment-card details or raw host/guest links in a support request.

Third-party services

PreOrderly currently uses Supabase for database and authentication services, Vercel for application hosting, Stripe for payment and subscription services, and Resend for transactional email. Provider access is limited to what is required to operate the service.

Continuous improvement

Security controls are reviewed as the product changes. Changes affecting authentication, authorisation, payments, public access links or personal information are expected to pass the repository verification pipeline before production deployment.

PreOrderly.

Group dining, organised.

ProductHow it worksFeaturesPricing
Built forVenuesHotelsEvent venues
CompanyResourcesSign inStart free
Trust & legalSecurityPrivacyTermsCookies