Encryption
Customer contact details are encrypted at rest with AES-256-GCM, and the encryption key is held outside the database — a database export alone exposes nothing readable. All traffic runs over TLS.
The strongest protection is data that isn't there. RelayLeads keeps only what a booking needs, encrypts it, deletes it on a timer — and keeps money and card numbers out of its systems entirely.
Customer contact details are encrypted at rest with AES-256-GCM, and the encryption key is held outside the database — a database export alone exposes nothing readable. All traffic runs over TLS.
Customer contact details auto-delete on a retention timer — 30 days by default, adjustable per business, and never past one year. Data that no longer exists can't leak.
Every business's data is scoped by application-level checks: the tenant is derived only from the authenticated operator's own record — never from a URL or request body — and re-verified on every read and write.
Card details are tokenized client-side and go directly to the business's own Stripe or Square account. RelayLeads is never in the funds flow and never stores card numbers.
Message delivery logs store no phone numbers and no message bodies — by schema, not policy. Push notifications to operators carry no customer data at all, just a secure pointer.
RelayLeads runs entirely on Cloudflare's global network — Workers, D1, KV, R2, and Queues. Uploaded photos are stripped of location metadata on both the client and the server before storage.
Found a vulnerability, or have a security question? Email [email protected] — security reports go to the top of the queue.
Claim your link. We build the rest.
Free, takes about two minutes, no credit card. Your page, booking flow, and dashboard — generated the moment you claim.