Security
Last updated September 2026
We handle bank details, VAT registration numbers, and receipts for real businesses. Here's how we protect that data. This page describes our current practices; it's a template you should validate against your actual infrastructure before publishing it as a formal security statement.
Data encryption
- All traffic to and from Rebound Nordic is encrypted in transit via TLS.
- Data at rest, including receipts and bank details, is encrypted in our database.
- Passwords are hashed and never stored or logged in plain text.
Access control
Your trip, expense, and payout data is only accessible to your own account, and to authorized Rebound Nordic staff handling your claim. Admin access to customer data is restricted and access-controlled at the database level, not just in the application UI.
Infrastructure
Rebound Nordic is built on Supabase (Postgres) with row-level security policies enforced at the database layer, so access rules apply even if application code has a bug, not just in the UI you see.
Payment and bank data
Bank account details you provide are used only to route your VAT refund payout and are never shared beyond what's required to complete that transfer.
Reporting a concern
If you believe you've found a security issue with Rebound Nordic, please email us at contact@reboundnordic.com. We take reports seriously and will respond promptly.
This is a starting template describing current practices, not a certified compliance statement.