Skip to main content
Sailia is designed to help you manage customer data responsibly. This page explains what data is collected, how it is stored, and the tools available to help you meet your privacy obligations.

What data Sailia collects

Sailia stores customer information needed to process bookings, manage accounts, and communicate with your customers.

Payment security

All card payments are processed through Stripe, which is PCI DSS Level 1 certified — the highest level of payment security certification. Sailia never stores, processes, or has access to full card numbers. When customers enter payment details:
  1. Card data is sent directly to Stripe’s servers.
  2. Stripe returns a secure token that Sailia uses for the transaction.
  3. Recurring payments for memberships and instalment plans use Stripe’s tokenized billing.
Because Sailia never handles raw card data, your PCI compliance scope is minimized. You do not need to complete a full PCI Self-Assessment Questionnaire for using Sailia.
When customers create an account on your booking page, they provide their information voluntarily. Customers can:
  • View their data — booking history, memberships, passes, and waivers are visible in their account
  • Update their details — customers can edit their name, email, and contact information
  • Manage marketing preferences — subscribers can unsubscribe from marketing emails through the link included in every campaign

Guest checkout

Customers who book as guests (without creating an account) provide only the information required to complete the booking. Their details are stored against the booking record but they do not have a login to manage their data.

Waivers and document storage

Waivers can collect sensitive information including signatures, health declarations, and uploaded documents. This data is:
  • Stored securely against the individual booking
  • Accessible only to staff with appropriate permissions
  • Linked to the specific participant who completed the waiver
If your waivers collect health or medical information, check your local regulations for any additional data handling requirements that may apply.

Staff access controls

Sailia’s permission system lets you control which staff members can access sensitive data:
Follow the principle of least privilege — give staff only the permissions they need for their role. See permissions reference for detailed recommendations.

Data in integrations

When you connect third-party integrations, data may be shared with external services:
Review the privacy policies of each third-party service you connect. You are responsible for ensuring these integrations comply with your local data protection regulations.

Data exports

Sailia provides several export options for extracting your data:
  • Booking exports — all booking records with customer details
  • Financial exports — payment and payout data
  • Customer exports — customer profiles and contact information
  • Donation exports — donation records with Gift Aid details
  • Timesheet exports — staff timesheet entries
Exports are generated as CSV files that you can download from the dashboard.

Best practices

  • Review staff permissions regularly — remove access for staff who no longer need it
  • Use waivers for consent — add a consent checkbox to your waiver templates for activities that require explicit data consent
  • Monitor marketing subscribers — respect unsubscribe requests and keep your audience list clean
  • Secure your account — use a strong password for your Sailia admin account
  • Audit integrations periodically — disconnect integrations you no longer use to minimize data sharing

Permissions reference

Control what each staff member can access.

Waivers

Collect consent and signed documents.

Payments and Stripe

How payment data is handled securely.

Customer accounts

How customers manage their own data.