Account And Workspace Access
- Organizer routes require an authenticated account before private workspace, event, CRM, billing, import, sponsor, or analytics data is shown.
- Workspace invitations, role permissions, owner recovery, and activity logs define who can manage events, guests, campaigns, billing, sponsors, imports, API keys, and enterprise controls.
- Protected API routes require session or scoped API-key authorization before accessing organizer-owned records.
Infrastructure And Enterprise Controls
- Cloudflare hosts the production application, database, storage, routing, and security edge controls.
- Enterprise settings support allowed origins, IP ranges, moderation rules, SSO configuration, data export controls, webhook settings, and security review evidence.
- API keys are stored hashed, rate limits are tracked, and webhook or partner operations include audit-oriented states.
Data Protection And Privacy
- Hobbybop avoids selling personal data and keeps organizer CRM, RSVP, import, email, billing, sponsor, and support data tied to workspace-controlled workflows.
- No-contact, unsubscribe, deletion, export, correction, and suppression workflows are routed through privacy and data-request handling.
- Some security, billing, audit, abuse, and fraud-prevention records may be retained where needed to protect people and the service.
Reporting Security Issues
Email support@hobbybop.com with the affected route, account or workspace context, request ID if available, and whether the issue exposes private data, payment state, published event access, or account control. Use /abuse for spam, impersonation, unsafe events, harassment, or exposed attendee data.