Last updated: July 2026
At Gleans, protecting your data is not an afterthought. It is foundational to how we build and operate the Service. This page describes the measures we take to keep your information secure.
In transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (SSL). This applies to the Gleans web application, API calls, and all integrations with third-party platforms.
At rest: Customer data stored in our databases and backups is encrypted using AES-256 encryption, the same standard used by financial institutions and government agencies.
Password security: User passwords are hashed using industry-standard algorithms (bcrypt) and are never stored in plain text. We enforce minimum password requirements to reduce the risk of compromise.
Session management: Sessions are time-limited and securely managed. Tokens are invalidated on logout and after periods of inactivity.
Internal access: Access to customer data within our team is strictly limited on a need-to-know basis. All internal access is logged and auditable. No member of the Gleans team can view your password.
Gleans is hosted on enterprise-grade cloud infrastructure with built-in redundancy, automated failover, and regular backups. Our hosting providers maintain industry-recognised certifications including SOC 2 and ISO 27001.
We deploy updates through a controlled release process with automated testing and staged rollouts to minimise the risk of service disruption.
Gleans does not store your full credit card details on our servers. All payment processing is handled by our PCI DSS-compliant payment processor. Your payment information is transmitted directly to the processor over encrypted channels and is never accessible to the Gleans application or team.
Each customer's data is logically isolated from other customers' data within our systems. Access controls ensure that you can only view and modify data belonging to your own account. Cross-account data access is not possible through the application.
When integrations are available and you connect Gleans to supported channels or property management systems, we use official APIs and OAuth-based authentication where available. We request only the minimum permissions necessary to provide the Service. Your credentials for third-party platforms are never stored by Gleans. Authentication is handled through secure token exchange.
Monitoring: We monitor our systems continuously for unusual activity, performance anomalies, and potential security threats. Automated alerts notify our team of any issues requiring attention.
Incident response: In the unlikely event of a data breach or security incident, we follow a structured response process:
(a) Immediately contain and investigate the incident.
(b) Assess the scope and impact on affected users.
(c) Notify affected users and relevant authorities (including the ICO where required) within 72 hours, as mandated by UK GDPR.
(d) Remediate the root cause and implement measures to prevent recurrence.
(e) Publish a post-incident report for transparency.
Customer data is backed up regularly to geographically separate locations. Backups are encrypted and tested periodically to ensure they can be restored in the event of data loss or system failure. Our recovery procedures are designed to minimise downtime and data loss.
All team members undergo security awareness training. Access to production systems and customer data is granted on the principle of least privilege and is reviewed regularly. We use multi-factor authentication for all internal systems and administrative access.
We regularly review our codebase and infrastructure for security vulnerabilities. Dependencies are kept up to date, and known vulnerabilities are patched promptly. We welcome responsible disclosure of security issues from external researchers.
If you discover a potential security vulnerability in the Gleans platform, we ask that you report it to us responsibly so we can investigate and address it before it is publicly disclosed.
Please report vulnerabilities to: security@gleans.io
When reporting, please include:
(a) A description of the vulnerability and its potential impact.
(b) Steps to reproduce the issue.
(c) Any supporting evidence (screenshots, logs, etc.).
We will acknowledge your report within 48 hours and aim to provide an initial assessment within 5 business days. We will not take legal action against researchers who report vulnerabilities in good faith and follow responsible disclosure practices.
Gleans is committed to compliance with applicable data protection regulations, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our Privacy Policy provides full details on how we collect, use, and protect your personal data.
If you have any questions about our security practices or wish to report a concern, please contact us at:
General enquiries: support@gleans.io
Security issues: security@gleans.io
Address: 69 Norwood Avenue, Romford, United Kingdom, RM7 0QL