Security
Security and trust
The directory is public. The work behind it is not. Here is how that line is actually drawn.
Last updated 30 August 2026

Private by default
Applications and uploaded files never touch a public URL
Access is logged
Ownership and permission changes are recorded
No card details held
Stripe handles cards. We never see them
Where we are today
The public directory and market-goer accounts are live. The organiser and stallholder tools are still in development, which means we are not yet holding applications, documents or payment records for anyone. When those open up, they open with the protections described here already in place.
How access works
Public pages and private records
Anyone can see a market page. Nobody can use that page to get at applications, uploaded permits, invoices, private notes or payment records.
Anyone can see
- Market name and location
- Dates and opening hours
- Photos and description
- Whether applications are open
Behind an account
- Stall applications
- Insurance and permit files
- Invoices and payment records
- Organiser notes and reviews
Seeing a market page has never been a way in to the column on the right.
A market can stay listed when applications are closed. Being visible is not the same as being open, and neither of those is the same as being accessible.
In place today
What is actually in place
Each part of MarketsGuide has its own front door. Sign-in on one is not a key to the others.
Route-level checks
Row-level access rules
Bot protection on sign-in
Signed file links
Security headers
Restricted admin access
Ownership and permission logging
Managed daily backups
Managed backups are run by our database host. We have not published a recovery time or recovery point objective, because we are not prepared to promise a number we have not tested properly. When we can stand behind one, it will go here.
Providers
Who else is involved
We use specialist providers to host the site, store records, send email, show maps, and take payments when that goes live. They only handle what they need to do their job. Some of that sits outside Australia.
The privacy policy names them, what they handle, and where. We update that list before we add a new provider that handles personal information.
Support access
Who can see your account
MarketsGuide is currently run by one person. To fix a fault, help with a support request, or look into a security problem, that person may need to open an account or a record.
That happens on an as-needed basis, limited to whatever the problem actually requires. It is not routine monitoring, and nobody is browsing your applications out of curiosity.
Incident response
If something goes wrong
2
business days to acknowledge a security reportThat is a target, not a guarantee.
If we become aware of a security incident affecting personal information, we will investigate it, contain what we can, and notify the people affected and the Office of the Australian Information Commissioner where the Privacy Act requires it.
If you think an account has been accessed without permission, or you have found a security problem, email hello@marketsguide.com.au with "Security" in the subject line. Please do not post exploit details publicly before we have had a chance to fix the issue.
What this page is not
This is a plain-English overview of how the product is built and run. It is not:
- a SOC 2, ISO 27001 or any other certification
- a signed Data Processing Addendum
- a promise that the service will never go down, never have a bug, or never be attacked
If your organisation needs a Data Processing Addendum or a completed security questionnaire, email us. Those are contract-stage documents and we will work through them properly.