Security

How Quick Flash looks after your business data, in plain terms for trades and SME teams.

Last Updated: July 22, 2026

1. What This Means for You

  • Private to your team. Only people in your company can see your jobs, clients, and quotes.
  • Secure sign-in. Your password is never stored in plain text, and sessions expire so forgotten tabs do not stay signed in forever.
  • Hosted in New Zealand. Our application servers run in NZ, with HTTPS protecting data on the way to and from the app.

2. Overview

Quick Flash is built for roofing and trades businesses that store jobs, clients, quotes, and team activity online. This page explains the practical steps we take to protect that information, without jargon or claims we cannot back up.

No online system is risk-free. We focus on strong account controls, encrypted connections, and clear boundaries so one company's users only see their own company's data.

3. Your Company, Your Access

  • You control who has access. Owners and admins invite teammates and set their role (for example owner, admin, project manager, or viewer) so staff only get what they need.
  • Only your team can see your jobs, clients, quotes, and invoices. People in other Quick Flash customers cannot browse your work.
  • When someone leaves, you can remove their access straight away.
  • If something looks wrong, support can lock the company account and force everyone out so the business stays protected while you sort it.

4. Sign-In and Sessions

  • Your password is never stored in plain text. It is saved as a secure hash before it ever sits in our system.
  • Web sign-in includes a CSRF check to help stop forged login requests from other sites.
  • Browser sessions expire about daily, so a forgotten tab does not stay signed in forever. Signing in again can end older browser sessions.
  • If you reset your password, existing web and mobile sessions are signed out so an old device cannot keep using the previous password.

5. Mobile App

  • The app keeps you signed in with a protected device token (iOS Keychain / Android encrypted storage), not by saving your password on the phone.
  • The mobile app connects to Quick Flash over HTTPS.
  • Signing in on a new phone signs out the previous one, so an old handset does not stay logged in after you move on.
  • Mobile sessions are time-limited and can be revoked from the server if needed.
  • Location, camera, and related permissions are only requested for specific job features such as clock in/out, job-site geofencing, photos and documents, and Tap to Pay, with explanations shown on the device.

6. Payments

  • Card payments are processed by Stripe. Quick Flash does not store full card numbers.
  • On mobile, Tap to Pay and card data stay in Stripe's payment stack. We do not keep full card numbers in the app.
  • Where we show a saved card, we only display details Stripe provides (such as brand, last four digits, and expiry).
  • Billing updates are verified as coming from Stripe, so forged webhook requests cannot quietly change your subscription.

7. Where Your Data Lives

  • Connections to Quick Flash use HTTPS, so data is protected in transit between your browser or phone and our servers.
  • Our application servers are hosted in New Zealand.
  • Some product features use trusted third-party services. Those providers process only what is needed for that feature, for example Stripe (payments), email delivery, maps and address lookup, accounting connections (such as Xero or QuickBooks), calendar links, and mobile push notifications.

For how we collect and use personal information, see our Privacy Policy.

8. Report a Security Issue

If you believe you have found a security problem in Quick Flash, please tell us. We take reports seriously and aim to respond promptly. Include enough detail for us to reproduce the issue (steps, screenshots, or affected account email).

Email: [email protected]