Skip to content
NeonO

Trust

Security and privacy, by default.

Your calendar, your client list and your money move through NeonO every day. Here is exactly how that data is protected, and what you can take with you if you ever leave.


Payments are handled by PCI DSS Level 1 processors

Card data is tokenized by the processor and never stored on NeonO servers. Tap-to-pay on a phone uses the device's certified secure payment stack, so raw card numbers never reach the app or your staff.

Encrypted in transit and at rest

All traffic runs over TLS 1.2+. Databases, backups and file storage are encrypted at rest. Internal service-to-service traffic is authenticated and encrypted.

Role-based access control

Owners, managers, front desk and stylists each see only what their role needs. Payroll figures, full client history and business reporting can be restricted to owners, and every sensitive action is written to an audit trail.

PIPEDA-aligned handling of client data

Client records are collected for a stated purpose, retained only as long as you need them, and deletable on request. You can fulfil an access or deletion request from the client record itself.

CASL-native marketing

Consent state, source and timestamp are stored on every contact. Campaign sends exclude contacts without valid express or implied consent, and unsubscribe handling is built in rather than bolted on.

Backups and recovery

Databases are backed up continuously with point-in-time recovery. Restores are tested, and recovery objectives are documented for the platform as a whole.

Operational practices

  • Documented incident response with defined severity levels and customer notification steps
  • Least-privilege internal access; production access is limited, logged and reviewed
  • Dependency and vulnerability scanning as part of the release pipeline
  • Change management: peer-reviewed code, staged rollouts and reversible deploys
  • Business-hours Canadian support for security questions and access requests

Your data stays yours

Clients, services, appointment history and sales export to standard CSV at any time, without asking support and without a fee. There is no lock-in clause and no export paywall. If NeonO stops earning your business, you should be able to leave with everything you brought and everything you built.

Reporting a vulnerability or need a security review for your own compliance file? Email security@neono.io.

Keep reading