Security

Security and trust

The directory is public. The work behind it is not. Here is how that line is actually drawn.

Last updated 30 August 2026

01

Private by default

Applications and uploaded files never touch a public URL

02

Access is logged

Ownership and permission changes are recorded

03

No card details held

Stripe handles cards. We never see them

Where we are today

The public directory and market-goer accounts are live. The organiser and stallholder tools are still in development, which means we are not yet holding applications, documents or payment records for anyone. When those open up, they open with the protections described here already in place.

How access works

Public pages and private records

Anyone can see a market page. Nobody can use that page to get at applications, uploaded permits, invoices, private notes or payment records.

Anyone can see

  • Market name and location
  • Dates and opening hours
  • Photos and description
  • Whether applications are open

Behind an account

  • Stall applications
  • Insurance and permit files
  • Invoices and payment records
  • Organiser notes and reviews

Seeing a market page has never been a way in to the column on the right.

A market can stay listed when applications are closed. Being visible is not the same as being open, and neither of those is the same as being accessible.

In place today

What is actually in place

Each part of MarketsGuide has its own front door. Sign-in on one is not a key to the others.

Route-level checks

Row-level access rules

Bot protection on sign-in

Signed file links

Security headers

Restricted admin access

Ownership and permission logging

Managed daily backups

Managed backups are run by our database host. We have not published a recovery time or recovery point objective, because we are not prepared to promise a number we have not tested properly. When we can stand behind one, it will go here.

Providers

Who else is involved

We use specialist providers to host the site, store records, send email, show maps, and take payments when that goes live. They only handle what they need to do their job. Some of that sits outside Australia.

The privacy policy names them, what they handle, and where. We update that list before we add a new provider that handles personal information.

Support access

Who can see your account

MarketsGuide is currently run by one person. To fix a fault, help with a support request, or look into a security problem, that person may need to open an account or a record.

That happens on an as-needed basis, limited to whatever the problem actually requires. It is not routine monitoring, and nobody is browsing your applications out of curiosity.

Incident response

If something goes wrong

2

business days to acknowledge a security reportThat is a target, not a guarantee.

If we become aware of a security incident affecting personal information, we will investigate it, contain what we can, and notify the people affected and the Office of the Australian Information Commissioner where the Privacy Act requires it.

If you think an account has been accessed without permission, or you have found a security problem, email hello@marketsguide.com.au with "Security" in the subject line. Please do not post exploit details publicly before we have had a chance to fix the issue.

What this page is not

This is a plain-English overview of how the product is built and run. It is not:

  • a SOC 2, ISO 27001 or any other certification
  • a signed Data Processing Addendum
  • a promise that the service will never go down, never have a bug, or never be attacked

If your organisation needs a Data Processing Addendum or a completed security questionnaire, email us. Those are contract-stage documents and we will work through them properly.