Trust center
Security & Privacy Center
Effective August 2, 2026What is private
Member identities, profiles, checkouts, orders, drops, PAS, invoices, webhook configuration, and workspace settings are private workspace data. They are available only to signed-in members of that workspace according to their assigned role.
Other ACO HQ customers cannot browse or query your workspace. Workspace boundaries are enforced in the database as well as in the application.
Who may access data
- workspace owners, admins, staff, or viewers authorized by the owner;
- protected ACO HQ server processes required to operate requested features;
- limited authorized ACO HQ personnel when needed for support, security, reliability, legal compliance, or abuse prevention; and
- infrastructure providers that host or transmit data under their own security and privacy obligations.
What ACO HQ does not collect
ACO HQ does not need or intend to store full credit-card numbers, CVV/CVC codes, PINs, magnetic-stripe data, or banking passwords. Whop hosts the subscription checkout and processes subscription payment details.
ACO HQ stores subscription status and membership identifiers needed to activate access. Detected card numbers and payment security codes are rejected from normal workspace writes and redacted from webhook archives and client diagnostics.
How data is protected
- database-enforced row-level security and workspace relationship checks;
- role-based access for owners, admins, staff, and viewers;
- authenticator-app two-step verification available to every account;
- encrypted network connections and encryption at the hosting and database layers;
- signed or secret-protected system webhooks with replay and rate-limit controls;
- masked integration destinations in the browser and server-only privileged credentials;
- audit records for sensitive workspace and delivery actions; and
- automated build and security-boundary checks before release.
Your security controls
- enable two-step verification from Account Security;
- invite only trusted teammates and assign the lowest role they need;
- remove team access immediately when it is no longer needed;
- keep Discord webhook URLs and scraper credentials private;
- never place payment-card or banking secrets in notes, uploads, or webhooks; and
- report suspected unauthorized access promptly.
Service providers and payment scope
ACO HQ currently relies on Whop for subscription billing, Supabase for authentication and database services, Vercel and Railway for hosting, Resend for transactional email, and Discord for selected authentication and messaging workflows. Using a hosted checkout materially reduces payment-data exposure, but no vendor statement replaces a merchant's own legal or PCI DSS obligations. Customers should direct subscription-payment questions to the checkout provider shown at purchase.
Questions, requests, and incidents
For a privacy request, suspected security issue, or question about data access, email acohqapp@gmail.com. Include your workspace name and enough detail to investigate, but never include passwords, authenticator codes, payment-card data, or webhook secrets in email.