Notice
The legal documents below apply to the French company RESAPASS TRAVEL. The French text is the authoritative version; an official English translation is being prepared. If you need clarification, please contact help@resapass.co.
Security & privacy
Resapass is a booking platform: we are transparent about how we store your data, who our subprocessors are and how to reach us on security matters.
Authentication & account
Sign-in uses secure sessions managed by our backend provider (Supabase). Passwords are hashed with bcrypt; multi-factor authentication is available on request for admin accounts.
Hosting & network
Front-end and edge routes run on Cloudflare (worldwide edge). Databases and file storage are hosted on Amazon Web Services in the European Union. All traffic is served over HTTPS with modern TLS.
Payments
Card payments are processed by Stripe. Resapass never stores raw card numbers; only Stripe tokens and last-4 digits are kept for support and reconciliation. Stripe is PCI DSS Level 1 certified.
Subprocessors
- Cloudflare — hosting & edge network
- Amazon Web Services — database & storage (EU)
- Supabase — managed Postgres & authentication
- Stripe — payment processing
- Mailgun — transactional emails
- Ratehawk — hotel inventory & booking
- Google Cloud (Gemini) — dynamic content translation
Data retention & deletion
See the privacy policy for full retention periods. You can request account deletion at any time by emailing help@resapass.co.
Report a security issue
Please email security@resapass.co with a description of the issue. We commit to acknowledging your report within 72 hours. Responsible disclosure is appreciated.
The French version at /securite is the reference document.