Security

Built to keep your shop's data safe

Your customer list, history and money live in Gravy. Here is how we protect them, in plain language.

Your data is yours Ask us anything
A separate database per shop

Your shop runs on its own instance with its own database, not a shared table alongside every other shop. Your records are isolated from everyone else's by design.

Encrypted in transit

Every page and connection is served over HTTPS. Data moving between you, your customers and Gravy is encrypted.

Role-based access

Owners, advisors and techs each get only what their job needs. You control who can see money, settings and customer data.

Backed up nightly, restore tested

Every shop's data is backed up automatically every night with consistent snapshots, kept on a separate volume, and the restore path is tested, not assumed.

Monitored 24/7 with auto-recovery

An automated health check runs every few minutes. If a shop's service hiccups it is restarted automatically, and we are alerted if anything stays down.

Card data stays with Stripe

Card payments are handled by Stripe. Full card numbers never touch or get stored on Gravy.

We never sell your data

Your records and your customers' information are never sold and never used to advertise to your customers. See our data page.

Take it with you, any time

One-click export of everything in standard CSV. No lock-in, no ransom to leave.

Straight talk: Gravy follows these practices today. We are not yet formally SOC 2 audited, and we will not claim a certification we do not hold. If your business needs specific compliance paperwork, tell us and we will be honest about where we are.

The binding details are in our Privacy Policy and Terms.