PaintBoss policies & trust

Security and Trust

How PaintBoss protects business accounts and how users share responsibility.

Last updated 28 August 2026Version 2026-08-28New Zealand
Written to be clear and practical

These policies explain how PaintBoss operates, protects information and supports the people and businesses using the platform.

Account protection

Passwords are hashed, staff access uses email multi-factor authentication, trusted devices expire or can be revoked, and sensitive authentication links are time-limited. Rate limits and abuse controls protect login and recovery flows.

Data protection

Business access is permission-controlled. Private job files and compliance documents are not served as public assets. Important integration credentials are encrypted and secret values are not displayed back to users.

Operational resilience

PaintBoss uses scheduled backups, controlled releases, recovery checkpoints, monitoring and documented rollback procedures. Backup restoration and retention are reviewed as operational controls; a backup is not considered useful until it can be restored.

Responsible use and reporting

Use a unique password, protect your email account, remove users who no longer need access and report suspected compromise promptly to admin@paintboss.co.nz. Do not send banking passwords, recovery codes or unrelated sensitive identity documents to PaintBoss.

Limit of this statement

This page is a plain-language security summary, not a guarantee or a substitute for the Privacy Policy, Terms of Service or an organisation’s own legal and record-keeping obligations.