Security and data

Your data, and what we do with it

UrusPro stores your operating data in a data centre in Tokyo, Japan, separates every organisation at the database level, keeps sensitive files in private buckets, and lets you export everything at any time. It operates under Malaysia's PDPA 2010. Each practice is explained below.

Practices

Separation at the database level

Every row knows which organisation owns it, and Row Level Security refuses requests from other organisations. The interface is not trusted to hide anything.

Sensitive files in private buckets

Payment proofs, IC photos, signatures and company stamps never become public URLs. They are read on the server and served through signed links that expire.

Roles, not one shared password

Staff, organisation admins and owners see different things. When someone leaves, their access is removed without changing anyone else's password.

Payments through a licensed gateway

Card numbers never touch UrusPro's servers. Online payments are processed by a licensed gateway in Malaysia.

Records that cannot be quietly deleted

Actions on bookings, payments and agreements leave a trail. Credit notes and cancellations are recorded, not deleted.

Export at any time

No data held hostage. Bookings, guests, collections and expenses can be exported to CSV from the portal.

Frequently asked questions

Data is stored on managed infrastructure in Tokyo, Japan. Files such as payment proofs, IC photos and signatures are kept in private buckets that cannot be reached without permission.

Report something

Found a security weakness, or have a question not answered here? Contact us at hello@uruspro.com. We reply to every security report.

See also the privacy policy and terms of use.