Security

Hobbybop security is designed around organizer-owned workspaces, scoped team access, hashed API keys, Cloudflare-hosted infrastructure, audit trails, and explicit escalation when account, payment, or attendee safety is at risk.

Account And Workspace Access

  • Organizer routes require an authenticated account before private workspace, event, CRM, billing, import, sponsor, or analytics data is shown.
  • Workspace invitations, role permissions, owner recovery, and activity logs define who can manage events, guests, campaigns, billing, sponsors, imports, API keys, and enterprise controls.
  • Protected API routes require session or scoped API-key authorization before accessing organizer-owned records.

Infrastructure And Enterprise Controls

  • Cloudflare hosts the production application, database, storage, routing, and security edge controls.
  • Enterprise settings support allowed origins, IP ranges, moderation rules, SSO configuration, data export controls, webhook settings, and security review evidence.
  • API keys are stored hashed, rate limits are tracked, and webhook or partner operations include audit-oriented states.

Data Protection And Privacy

  • Hobbybop avoids selling personal data and keeps organizer CRM, RSVP, import, email, billing, sponsor, and support data tied to workspace-controlled workflows.
  • No-contact, unsubscribe, deletion, export, correction, and suppression workflows are routed through privacy and data-request handling.
  • Some security, billing, audit, abuse, and fraud-prevention records may be retained where needed to protect people and the service.

Reporting Security Issues

Email support@hobbybop.com with the affected route, account or workspace context, request ID if available, and whether the issue exposes private data, payment state, published event access, or account control. Use /abuse for spam, impersonation, unsafe events, harassment, or exposed attendee data.