Information security policy
Last updated: 2026
Our approach
We rely on established, security-audited infrastructure rather than building our own, and restrict data access as narrowly as possible, both for visitors and for our own team.
How data is protected
- All traffic to CompareHQ is encrypted in transit (HTTPS).
- Passwords are never stored or seen by CompareHQ in plain text, they're handled entirely by our authentication provider, Supabase, using industry-standard hashing.
- Database access is restricted using row-level security policies, enforced at the database itself, not only in our application code. A buyer can only reach their own account data, a provider only their own listing and the quote requests sent to them through their account (direct enquiries are emailed to a provider when submitted, rather than stored in a dashboard they can browse later).
- Internal access to buyer and provider data is limited to named staff who need it to operate the platform, gated by a separate staff-membership check.
Our infrastructure
CompareHQ is built on established providers rather than self-hosted infrastructure: Supabase (database and authentication), Vercel (hosting), and Resend (email delivery). See our Data processing & sub-processors page for detail on each.
If something goes wrong
We have an internal incident response process covering detection, containment, and notification, in line with UK GDPR requirements. See our Data protection policy for what happens if a breach occurs.
Reporting a security concern
If you believe you've found a security vulnerability on CompareHQ, please report it responsibly by contacting us directly rather than disclosing it publicly, and we'll investigate promptly.
