Last updated: September 27, 2026
Report a security issue: security@meloraconnect.com. Support: support@meloraconnect.com or (571) 290-2703.
1. Where Melora Connect runs
1.1 The application runs on Cloudflare’s network. Data, sign-in and files are stored with Supabase, a managed database and storage provider, in Canada (Amazon Web Services, Montreal). Payments are processed by Stripe. The full list of providers is in our Privacy Policy.
1.2 Connections to Melora Connect use HTTPS. Plain HTTP requests are redirected to HTTPS, and browsers are told to use only HTTPS for our domain.
2. Keeping each organisation’s data separate
2.1 Access rules are enforced in the database itself, not only in the app. Row-level security rules decide which rows each signed-in user can read or change, based on their organisation and role. This is designed so that one Association cannot see another Association’s data, and a member sees only what their Association allows.
2.2 Association administrators control staff roles and permissions. Sensitive actions, such as approving payments or countersigning contracts, need specific permissions.
2.3 Uploaded files, such as member documents, vendor documents and application uploads, are kept in private storage. Profile photos are public by design.
2.4 Melora staff access. Melora staff have no standing access to an Association’s member, payment or other records. A staff member who needs it, mainly to help with a support request, asks for access to that one Association, with a written reason and a time limit of one hour to one week. One of a small number of designated approvers at Melora must approve it, nobody can approve their own request, and the access ends by itself when the time runs out or when it is revoked. These rules are enforced in the database, and every request, approval, view and revocation is recorded. Help requests sent to Melora are handled by our support team without this approval.
3. Signing in
3.1 Accounts sign in with an email address and password through Supabase Auth. Passwords must be at least 8 characters and are never stored by Melora in readable form.
3.2 Sign-up, sign-in, password reset and invitation pages use Cloudflare Turnstile to block bots.
3.3 Multi-factor authentication is not available yet (see Section 14).
4. Payments
4.1 MeloraPay runs on Stripe Connect. Card details are entered in Stripe’s own payment forms and go straight to Stripe; they do not pass through or get stored on Melora’s servers.
4.2 Stripe collects identity documents and bank details directly during onboarding. Melora never collects, stores, logs or transmits tax identification numbers, bank account or routing numbers, or dates of birth.
4.3 Every charge is made on the Association’s own Stripe account, and the code refuses to charge without one, so member money never lands in Melora’s balance by mistake.
4.4 Messages from Stripe and our email provider are accepted only when their signatures verify. Scheduled internal jobs require a secret key.
5. Encryption
5.1 Data is encrypted in transit with HTTPS and encrypted at rest by our database and storage provider. Melora does not add its own field-level encryption, and messages are not end-to-end encrypted; Section 8 explains who can read them.
6. Protection against abuse
6.1 Public forms and sensitive endpoints are rate limited. For example, a single email address can submit only 3 vendor applications a day, and address search is limited per user.
7. Audit logs
7.1 Important actions, such as application submissions, contract signatures, account deletions and permission changes, are recorded in an audit log. Association administrators can review their organisation’s audit log in the admin portal.
8. Messages
8.1 Messages are stored on our systems. Inside Melora Connect, a conversation can be read only by the people in it and the Association staff who manage that area. Melora staff do not read messages in the normal course of business; a small number of engineers with database administration access can reach them when needed to investigate a reported problem, keep the platform safe or meet a legal requirement.
9. Monitoring without personal data
9.1 We use error monitoring to find and fix problems. Error reports carry an internal user ID and organisation ID, and are configured not to include names, email addresses, IP addresses, cookies or sign-in headers.
10. No tracking or advertising
10.1 Melora Connect has no advertising trackers and no analytics trackers. See the Privacy Policy for the browser storage we do use.
11. Backups and deleting data
11.1 The database is backed up every night. Each backup is encrypted before it is stored, is kept with Cloudflare, separately from our database provider, and is deleted after 30 days. Only named Melora key holders can decrypt a backup, and we test restoring from them.
11.2 When a member or vendor deletes their account, the sign-in account is deleted and the deletion is recorded in the audit log. Remaining copies in backups are removed as backups rotate.
12. Security incidents
12.1 If we confirm a security incident that affects your personal information or your organisation’s data, we will tell affected account owners without undue delay, and no later than 72 hours after confirming it, with what happened, what we are doing and what you should do. Associations are responsible for notifying their own members where the law requires, and we will give them the information they need.
13. Reporting a vulnerability
13.1 If you find a security issue, email security@meloraconnect.com with the steps to reproduce it. We will acknowledge your report within 2 business days and aim to fix or mitigate confirmed issues within 30 days, depending on severity.
13.2 Please give us reasonable time to fix the issue before disclosing it. Do not access, change or delete data that is not yours, do not disrupt the Service, and do not use social engineering. We will not take legal action against good-faith research that follows these rules, and we will credit you if you want us to.
14. What we are working on
14.1 These controls are planned and not available yet:
- Multi-factor authentication, with an option for Associations to require it for administrators.
- Automatic session timeout settings.
- IP address allowlists for administrator access.
- Single sign-on for Enterprise plans.
14.2 Melora does not currently hold security certifications such as SOC 2 or ISO 27001.