Security
Last updated: July 2026
Protecting the data that studios, instructors, and members entrust to StudioWhirl is a core part of how we build and operate the Service. This page outlines the key practices we follow to help keep that data safe.
Payments infrastructure
All payments and payouts run through Stripe and Stripe Connect, a PCI Service Provider Level 1 platform, the highest level of certification available in the payments industry. StudioWhirl never stores full card numbers or bank account numbers on its own servers.
Encryption in transit and at rest
Data sent to and from StudioWhirl is encrypted using TLS. Data stored in our databases and backups is encrypted at rest using industry-standard encryption.
Infrastructure and hosting
StudioWhirl runs on Cloudflare's global network, which provides distributed denial-of-service (DDoS) protection, network-level security controls, and redundancy across multiple regions.
Access controls
Studio owner accounts control who on their team can view schedules, bookings, and payout information, through role-based dashboard permissions. Internal access to production systems is restricted to authorized StudioWhirl team members and logged.
Monitoring and logging
We monitor our systems for suspicious activity and maintain audit logs to help detect and respond to potential incidents quickly.
Vendor and subprocessor due diligence
We rely on a small number of well-established subprocessors — Stripe for payments and payouts, and Cloudflare for hosting and infrastructure — and review their security practices before relying on them to handle studio or member data.
Regular reviews
We periodically review our security practices and dependencies, and apply patches and updates in a timely manner.
Responsible disclosure
If you believe you've found a security vulnerability in StudioWhirl, please report it responsibly through our Contact page so our team can investigate promptly. We ask that you do not publicly disclose the issue until we've had a reasonable opportunity to investigate and address it.
Your responsibilities
Security is a shared responsibility. We recommend enabling strong, unique passwords for every account, and studio owners should limit staff dashboard access to only what each team member needs.
For details on how we collect, use, and protect personal information, see our Privacy Policy.