RidenRank Ltd
Security
Last updated: 30 September 2026
This page describes how RideDesk protects operators’ data in practice. It is written to be checked: each point names what is done, not what is intended. Where something is not yet in place, the last section says so.
1. Where your data lives
- The application database, authentication and document storage run on Supabase in the European Union.
- Email is sent and received through Amazon SES in the EU (Frankfurt, eu-central-1) and stored with the EU-region database.
- The application runs on Cloudflare Workers at the network edge, behind Cloudflare’s web application firewall and bot protection.
- The full list of providers, their locations and the transfer safeguards is on the sub-processors page, and we notify operators before adding one.
2. One organisation, one tenant
- Every row of operator data carries the organisation it belongs to, and the database enforces row-level security on that organisation.
- The application scopes every read and write to the organisation resolved from the signed-in session or the host it is served on, as a second layer over the database rule.
- A staff login sees only the organisations it is a member of. Platform staff can open an operator’s panel for support, under their own named login.
- Operators connect their own payment accounts (Stripe, PayPal, SumUp, Square, Mollie, GoCardless), so money and card details flow between their customer and their own provider, not through a shared merchant account.
3. Accounts and access
- A new account proves it owns its email address with a one-time code before anything is created; the company domain must exist in DNS; sign-ups are rate-limited per address and per network.
- Staff have one of four roles — owner, admin, dispatcher, member — and the panel’s actions check the role on the server, not only in the interface.
- Sessions use HttpOnly cookies with rotating, single-use refresh tokens. Staff login events (time, network, country) are kept for 180 days as a security log.
- Changes to bookings, customers, prices and settings are written to an audit trail with who did what and when. Access to customers’ identity documents is recorded there too.
- Driver and partner links are per-person tokens that open only that person’s jobs; they carry no panel access.
4. Transport and the application
- All traffic is HTTPS. The ridedesk.app domain is on the browsers’ HSTS preload list, so a plain-HTTP connection is never attempted.
- Pages are served with a restrictive content security policy and the usual hardening headers (frame, content-type and referrer controls).
- Public forms — quotes, enquiries, sign-up — are protected by Cloudflare Turnstile, and the public quote endpoint is rate-limited per network.
- Incoming webhooks from Meta (WhatsApp) and Stripe are verified against their signatures before anything is processed; an unsigned or mis-signed call is dropped.
- A WhatsApp number or business account can be attached to one organisation only; the database refuses a second claim on the same identity.
5. Secrets, integrations and AI
- Third-party credentials and access tokens an operator connects are encrypted at rest with AES-256-GCM and are never sent to the browser.
- RideDesk never stores card numbers: payment details are entered on the payment provider’s own hosted fields or pages.
- Before any text reaches an AI model, email addresses and phone numbers in it are replaced with placeholders; the model never receives them. The log of AI requests is kept for 90 days for billing and abuse checks, then deleted.
- AI features draft; a member of staff decides what is sent. A quote drafted by the assistant goes to a customer only after a person has reviewed it.
6. Retention
- Network addresses and browser details on website quotes are removed after 90 days; the anonymous funnel row is kept.
- WhatsApp and website chat conversations are deleted after 180 days. Deleted mail leaves the trash after 30 days.
- Staff login events are kept for 180 days; link-open telemetry and the network-to-city cache for 90 days; driver positions for at most 12 hours.
- Invoices and tax records are kept for six years, as accounting rules require. The full schedule is in section 10 of the privacy policy.
- An operator can export or erase a customer’s personal data from the panel, and can delete their own staff login at any time.
7. Reporting a vulnerability
If you believe you have found a security issue, email hello@ridenrank.com with enough detail to reproduce it. Please do not access data that is not yours, and give us reasonable time to fix the issue before publishing it. We reply to every report.
8. What is not yet in place
- RideDesk holds no SOC 2 report or ISO 27001 certificate. We will say so here until that changes.
- There is no public status page yet. Incidents are communicated to affected operators by email.
- Two-factor authentication for staff logins is not yet offered.
- Database backups are taken by the database provider; a published, tested restore schedule is not yet part of this page.
Last reviewed 2026-09-30. Questions about any point: hello@ridenrank.com.