Trust Center

    Trust & Security

    This page is maintained by Waiver Hog to answer the common security and privacy questions businesses ask before they put their waiver program on our platform. It describes how the product works today.

    Not a certification. The statements here describe controls that are enabled in our product and capabilities of the infrastructure we build on. They are not an independent audit, an attestation, or a certification of any standard.

    Shared responsibility. Our platform provides the controls; each business decides what data its waivers collect, who on its team has access, which integrations to connect, and what it tells its own guests.

    Access & authentication

    • Business accounts sign in with email and password; sessions are issued and refreshed by our authentication provider.
    • Admin areas support role-based permissions so staff only see the tools their role allows.
    • Sensitive admin actions can be protected with a PIN in kiosk and shared-device settings.
    • Every account's data is isolated at the database level with row-level security policies, so one venue cannot read another venue's records.

    Platform & hosting

    • Waiver Hog runs on Lovable Cloud, which is built on Supabase (Postgres, Auth, Storage, Edge Functions) and served over HTTPS.
    • Traffic to waiverhog.com is served over TLS with HSTS enabled.
    • Application data is stored in managed Postgres; signed waiver documents are stored in managed object storage with non-public access paths.

    What we collect and why

    • Waiver participants provide the fields your business configures on its waiver — typically name, date of birth, contact details, guardian details for minors, and a signature.
    • Optional features you enable may capture a photo, an uploaded ID document, or additional custom fields.
    • We process this data to produce, store, and deliver the signed waiver record to the business that collected it. Participant data belongs to that business.
    • Basic product analytics and error logs are collected to keep the service working.

    Subprocessors & integrations

    • Supabase (via Lovable Cloud) — database, authentication, file storage, and serverless functions.
    • Resend — transactional email such as waiver copies and account notifications.
    • Twilio — SMS and voice features, where enabled by the business.
    • Stripe — payment processing, where enabled by the business. Card data is handled by Stripe; we do not store full card numbers.
    • Booking system integrations (for example FareHarbor, Peek Pro, Xola, Rezdy, Checkfront and others) exchange booking and participant data only when a business connects them.

    Signed waiver records

    • Each completed waiver is rendered to a PDF and stored against the participant and booking record.
    • Access to a signed waiver requires either an authenticated staff session for that account or a signed, expiring link.
    • A copy of the signed waiver is emailed to the signer when an email address is provided.
    • Waiver activity is written to an audit trail so a business can see who signed what and when.

    Retention & deletion

    • Waiver records are retained for as long as the business keeps its account, because liability records generally need to be retrievable long after the visit.
    • Operational data such as analytics events and error logs is retained on a rolling window rather than indefinitely.
    • A business can request deletion of its account and associated records by contacting support; a participant should contact the business that collected their waiver, or contact us and we will route the request.

    Privacy requests

    • For access, correction, or deletion requests, email support@waiverhog.com from the address on file and describe the request.
    • Where a request concerns a waiver collected by one of our customers, that business is the data controller and we act on their instruction.
    • Our full privacy terms are published on the Privacy Policy page.

    Security contact & vulnerability reporting

    • Report a suspected vulnerability or security concern to support@waiverhog.com with the subject line 'Security'.
    • Please include reproduction steps and avoid accessing, modifying, or exfiltrating data that is not yours.
    • We will acknowledge reports and follow up with the reporter as we investigate.

    Questions we haven't answered here

    If you need details on a specific control, a data processing agreement, or documentation for a procurement review, get in touch and we will answer directly.

    support@waiverhog.com

    See also our Privacy Policy, Terms of Use, and all policies.