Security at Seamless
Your event data - speakers, schedules, attendees, content - is the core of what you trust us with. Here is exactly how we protect it, in plain terms.
Infrastructure
Seamless runs entirely on managed, security-hardened cloud infrastructure - we operate no raw servers, and production is fully isolated from our beta environment.
Google Cloud
The API runs on Cloud Run - patched, auto-scaling containers with TLS enforced on every request. The app and this website are served by Firebase Hosting.
CockroachDB
Your data lives in a distributed SQL database with a dedicated production cluster, fully separate from our staging database.
Cloudflare
The website and API are served through Cloudflare's global network, which absorbs DDoS traffic before it reaches us.
Your data, protected
Encrypted in transit and at rest
All traffic is TLS-encrypted. The database is encrypted at rest, and credentials for connected integrations are additionally encrypted before they are ever stored.
Located in the EU
Our primary data stores run in Belgium (Google Cloud, CockroachDB) and Western Europe (Cloudflare R2, where event files live).
Backed up automatically
Daily full database backups with 30-day retention, managed automatically by CockroachDB Cloud.
Kept to a minimum
We only process the attendee and event data you enter, on your behalf - we don't sell it, share it, or use it for anything else.
Access & authentication
No passwords on our servers
Sign in with Google, Microsoft, or email - authentication is handled entirely by Firebase Authentication (Google's identity infrastructure). Passwords never reach our systems.
Signed, authenticated sessions
Every API request carries a signed token, checked against your role and permissions before any data moves.
Role-based access control
Built into the product: organization admins and editors with fine-grained, per-capability permissions, enforced on every API request.
Payments that never touch our servers
Checkout and payments are handled by Polar (our merchant of record) and Stripe for organizer payouts. Card numbers are entered on their compliant checkout pages - they are never stored on or transmitted through Seamless infrastructure.
You stay in control
Delete your account yourself, anytime, from account settings - no support ticket required.
Data processed on your behalf - you remain in control of your data and can request deletion at any time, as described in our Privacy Policy.
Subprocessors
These providers process data as part of delivering the service:
| Provider | Purpose |
|---|---|
| Google Cloud (Firebase) | Application hosting, authentication |
| Cockroach Labs | Primary database (EU region) |
| Cloudflare | CDN & DDoS protection, event file storage, DNS |
| Polar | Payments - merchant of record |
| Stripe | Organizer payouts (Stripe Connect) |
| Brevo | Transactional email |
| Microsoft | Sign-in provider |
Report a vulnerability
If you've found a security issue, please tell us: email security@seamlessevents.io and we'll acknowledge your report and act on it. We'd rather hear from you than find out the hard way.
Questions about data protection or privacy? Contact us - see also our Privacy Policy, Terms & Conditions, and Cookie Policy.