Security & data protection

This page is maintained by the Shift4 Referrals team to answer common security and privacy questions about the platform. It describes the controls we have enabled today; it is not an independent certification or audit report.

Encrypted bank details

UK account numbers and sort codes are encrypted at the application level before being stored. They are only decrypted when a staff member or admin explicitly chooses to reveal them, and that access is logged.

Role-based access

Every user is assigned a role — customer, staff or admin. Row-level security policies make sure customers can only see their own applications, while staff and admin permissions are scoped to their duties.

Audit logging

Key events such as application creation, status changes, role grants and bank-detail access are recorded in an immutable audit log.

Secure hosting

The portal is hosted on Lovable Cloud with HTTPS enforced for all traffic. Authentication, database and storage are managed through the same secure backend infrastructure.

Least-privilege data handling

Bank details are not included in printable summaries, WhatsApp messages or customer-facing progress views. Staff must explicitly reveal them to see the full values.

Security contact

If you discover a security issue or have a question about our controls, email us at support@shift4referralportal.co.uk.

Shared responsibility

Lovable Cloud provides the secure platform, infrastructure and managed services that power this application. The portal owner is responsible for how data is collected, how long it is kept, and who within the organisation can access it. Customers are responsible for keeping their account credentials safe and using strong passwords.

Chat with EMS