Security at SeatLayer
How we protect your data and your buyers’ data.
Protecting your data
The measures we apply to every account.
In transit and at rest
All traffic to SeatLayer uses HTTPS. Stored data is encrypted at rest.
Limited to people who need it
Only authorised staff who need access to run or support the service can reach customer data. Each organizer’s data is kept separate from every other organizer’s.
No passwords to steal
Dashboard sign-in uses a one-time code sent by email. API keys can be rotated or revoked at any time, and test and live keys are kept separate.
Card details stay with your payment provider
Buyers pay through the payment provider you connect. SeatLayer never stores complete card details.
Data protection
Our Data Processing Agreement applies to every account.
Germany
Customer data is stored in Germany. Uploaded files are stored in the Asia-Pacific region.
DPA with Standard Contractual Clauses
Our Data Processing Agreement includes the EU Standard Contractual Clauses. Organizers can see our subprocessors in the dashboard under Settings → Data protection.
Access, correct or delete
Email hello@seatlayer.io to access, correct, export or delete personal data. We reply within one month.
Availability, backups and changes
Check the service status and our change history at any time.
Daily backups
Our main database is backed up every day, and backups are kept for 7 days.
Published changelog
Changes to the SDK and API are published in our changelog.
Open the changelog →Integrating securely
How to use API keys, embed sessions and webhook signatures in your integration.
Authentication → · Webhook signatures →getseatlayer.com · seatlayer.dev · seatlayer.events
getseatlayer.com is an outreach sender domain and redirects to seatlayer.io. seatlayer.dev is an outreach sender domain and redirects to seatlayer.io/developers/. seatlayer.events is the customer storefront namespace. Account sign-in remains on app.seatlayer.io.
Found a vulnerability?
Email us with enough detail to reproduce it, and give us a reasonable time to investigate and fix it before disclosing it publicly. For security questions during an evaluation, contact us.
hello@seatlayer.io