Last updated 7 September 2026
Security policy
We run Urban Assist as a marketplace that handles your identity, home address, and payments. This policy explains the measures we take to keep those things safe and what happens if something goes wrong.
How we protect your data
- Encryption in transit and at rest — all traffic is over TLS (HTTPS); databases are encrypted at rest.
- Authentication without passwords — sign-in is by one-time code, so we do not store passwords that could be reused elsewhere.
- Least privilege and access control — access to bookings, messages, and payments is scoped to the signed-in account and enforced at the database level.
- Isolated execution — payment handling is isolated from general application code; card details go directly to Stripe and never reach our servers.
- Logging and monitoring — access and booking events are logged so we can detect and investigate anomalous activity, including automated error monitoring.
- Backups — automated database backups support recovery in a disaster. We test restores periodically; no backup strategy can guarantee zero data loss in every scenario.
Payments
Card payments are processed by Stripe. Card numbers, expiry dates, and CVCs are entered into Stripe's hosted form and are not stored on Urban Assist servers. We store only the payment reference, amount, and status needed to receipt and support your booking.
We do not ask for payment details by message, email, or phone. If someone does, stop and contact info@urbanassist.co.uk.
What we ask of you
- Keep your contact details accurate and the property available at the agreed time.
- Do not share verification codes or give others access to your account.
- Keep arrangements and payments on the platform — off-platform work removes protection for both sides.
- Tell us promptly if you suspect unauthorised access to your account.
Our people and suppliers
Staff access to personal data is restricted to those who need it for their role, and is conditioned on confidentiality. Our third-party processors and international transfer safeguards are set out in our Data processing agreement and Privacy notice.
Vulnerability reporting
If you discover a security vulnerability, tell us privately so we can fix it before it is abused. See our Responsible disclosure page for how to report, what to include, and our safe-harbour promise. Do not use vulnerability reports to access or exfiltrate data.
Incident and breach response
When we become aware of an incident that affects your data or payments:
- We contain and assess the incident and work to restore service.
- Where the incident is a personal data breach, we assess the risk to individuals and notify the ICO within 72 hours where required by UK GDPR. If the risk is high, we inform affected users directly and without undue delay.
- We review the cause and apply fixes to prevent recurrence.
- We keep a record of the breach as required by law.
Updates to this policy
We review this policy on each significant platform change and at least annually. Changes are published here; where a change affects how we handle security-relevant behaviour, we will tell you before it takes effect.
Questions? Email info@urbanassist.co.uk. For personal data matters, see our Privacy notice.
