Your business. Your data.
SPAFITI stores account details, business records, customer contacts, appointments, sales and stock movements to operate your workspace. Each business controls its own customer records and marketing consent.
Access and security
Access is controlled by account roles and tenant-scoped server queries. Passwords are hashed. Session tokens are stored in HTTP-only cookies and hashed in the database. Payment credentials remain on the server.
Connected providers
When enabled, payment and messaging providers receive only the details required for the requested transaction or message. AI requests use business summary data through the configured provider. Do not store confidential medical information in free-text notes.
Your choices
Business owners are responsible for obtaining consent, managing access, responding to customer data requests and setting retention policies. Contact your business directly about its customer records. Platform enquiries can be submitted through the contact form.
This draft must be reviewed and completed with the operating company’s legal identity, privacy contact, retention periods and cross-border processing arrangements before public launch.
Contact SPAFITI