Last updated: March 13, 2025
At Paidnice, safeguarding your data is our top priority. We employ robust security measures and adhere to strict data protection protocols to ensure the confidentiality and integrity of your information.
Data Handling and GDPR Compliance
Paidnice does not store any accounting data. Instead, we connect securely to your accounting platform (like Xero or QuickBooks) via their official APIs and display or process data in real-time. We do not extract, replicate, or persist financial data on our infrastructure.
- Your data stays where it already lives – in Xero or QuickBooks.
- We follow data minimization principles: only accessing what's necessary for core functionality.
- For more, see Xero's GDPR Statement.
Access Controls
Staff Login & Internal Access
- Google Workspace authentication with enforced strong passwords.
- Mandatory 2FA for all internal systems.
- Password manager use required for unique, secure credentials.
- Full audit logs of staff access activity.
Application Servers
- Hosted on Salesforce Heroku, a secure, multi-tenant cloud platform.
- Access limited to engineering team and senior leadership.
- 2FA login with full access and activity logging.
External Systems
Source Code
- Managed in GitHub with enforced 2FA.
- All changes reviewed and deployed via GitHub Actions.
- Role-based permissions to limit scope of access.
Customer Tools & Billing
- Intercom for support communication (Google SSO + 2FA).
- Mixpanel for behavioral analytics.
- Stripe for billing - Paidnice does not store or process credit card data.
- Senior staff only access sensitive external systems.
Software Controls
Authentication & Access
- End-user login managed via Auth0 (Okta).
- All third-party tokens encrypted using AES-256.
- Application access logs are maintained in Google Cloud.
Data Security
- Data encrypted in transit using TLS (SSL).
- At rest, encrypted using AES-256 with block-level storage.
- Continuous automatic backups via Heroku Continuous Protection.
We’re committed to transparent, secure, and privacy-respecting practices that meet the standards expected by financial services and enterprise customers. If you have security questions or need documentation for compliance reviews, reach us directly at hello@paidnice.com.