This page is maintained by the Shift4 Referrals team to answer common security and privacy questions about the platform. It describes the controls we have enabled today; it is not an independent certification or audit report.
UK account numbers and sort codes are encrypted at the application level before being stored. They are only decrypted when a staff member or admin explicitly chooses to reveal them, and that access is logged.
Every user is assigned a role — customer, staff or admin. Row-level security policies make sure customers can only see their own applications, while staff and admin permissions are scoped to their duties.
Key events such as application creation, status changes, role grants and bank-detail access are recorded in an immutable audit log.
The portal is hosted on Lovable Cloud with HTTPS enforced for all traffic. Authentication, database and storage are managed through the same secure backend infrastructure.
Bank details are not included in printable summaries, WhatsApp messages or customer-facing progress views. Staff must explicitly reveal them to see the full values.
If you discover a security issue or have a question about our controls, email us at support@shift4referralportal.co.uk.
Lovable Cloud provides the secure platform, infrastructure and managed services that power this application. The portal owner is responsible for how data is collected, how long it is kept, and who within the organisation can access it. Customers are responsible for keeping their account credentials safe and using strong passwords.