How we protect your data
Peach holds your customer records, your booking history, and a live connection into your CRM. Here is where that data sits, who can reach it, how long we keep it — and which controls we haven't built yet.
Where we stand on SOC 2
We don't hold a SOC 2 report, and we're not going to imply we do. What we do have is a written control program: access control, encryption in transit, data classification and retention, incident response, audit logging, secret lifecycle, and vendor management are each a versioned policy with a named owner and a review date. We'll walk you through any of them under NDA.
Data in transit
Traffic between your browser, your CRM, and Peach runs over TLS 1.2 or higher, and 1.3 where both ends support it. TLS 1.0, 1.1, and SSL are turned off, and plain HTTP is redirected at the edge and again inside the app so a misconfiguration can't leak it. Our database and cache connections require TLS too.
Data at rest
CRM tokens, OAuth refresh tokens, and telephony keys are encrypted with AES-256-GCM before they're written to the database, so a database dump on its own doesn't hand anyone your integrations. Storage and backups are encrypted by our managed database and object-storage providers. Card numbers never reach Peach at all — Stripe handles payments.
Hosting and residency
Peach runs on managed cloud infrastructure in a US East region, with a staging environment that has its own database, its own cache, and its own secrets — it never touches production data. Your data stays in the United States. We have no EU operations, so GDPR doesn't apply; California customers are covered under CCPA.
Sign-in and staff access
You sign in with email and password on a verified address, or with Google. Login attempts are rate-limited. On our side, the staff admin console requires MFA, and our access policy is that nobody holds standing production database access — it's requested when it's needed, time-boxed, and reviewed every 90 days. Emergency access is possible, but it always leaves an audit trail.
Sub-processors
A short list of vendors runs pieces of Peach: hosting, database, cache, object storage, telephony, email, payments, AI models, and error monitoring. Each one sits in an internal vendor inventory with a risk rating, a named internal owner, and its agreement status, reviewed quarterly. Ask and we'll send you the current list.
Retention and deletion
Every column in our database carries a sensitivity tag, and each class has a retention period. Customer records are kept while you're a customer plus 90 days, then deleted. Billing records are kept seven years because tax law requires it. Operational logs are kept 90 days. You can ask for an export or a deletion at any time.
Common questions
Do you have a SOC 2 report?
No. There is no completed audit, and we'd rather tell you that than dress up a timeline. Our written policies are organized against the Trust Services Criteria and we'll share them under NDA. If your procurement process needs a report in hand before you can sign, say so early and nobody wastes a month finding out.
Who at Peach can see our customer data?
A small number of staff, through an admin console that requires MFA. Every cross-tenant read and every impersonation session is written to an admin audit log with the company it touched, alongside role changes, integration changes, and secret rotations. Nobody gets quiet access.
What happens if there's a security incident?
We run a written incident process with severity levels. A confirmed breach or any cross-tenant data leak is our highest severity: status page inside an hour, affected customers notified within 24 hours of confirmation, and a post-incident review written up within five business days. A single-customer incident is notified within four hours.
Can we get our data out, or deleted?
Either one, on request, and the request itself is logged. After you cancel, customer records are deleted 90 days past the end of the grace period. Billing records stay seven years for tax. Credentials we hold for your integrations are destroyed when you disconnect them.
Doing a security review?
We'll send our written policies — access control, encryption, classification and retention, incident response, audit logging, vendor management — plus the current sub-processor list, under NDA. There is no SOC 2 report in that bundle, for the reason above.