Skip to main content
Menu
Log in Start

Security and data practices

Protect the records that keep a grooming day moving.

OpenDog uses practical account, session, access, shop-data, request, import, and payment boundaries around the client and dog details your team needs. This page explains the controls that are implemented today, the limits they do not erase, and the habits every grooming business still owns.

  • Authenticated business workspace
  • Role and shop boundaries
  • No blanket certification claims
OpenDog pet record using sample data, showing the owner, handling alert, breed, sex, birth year, and care context inside an authenticated business account.

Public request boundary

A request reaches review-not an open staff workspace.

The customer-facing form gathers the details needed to ask for service. The grooming business reviews the client, dog, service, address, timing, notes, and route fit inside its authenticated workspace before creating an appointment.

OpenDog request review using sample data, showing a linked client and dog while the appointment remains unconfirmed inside the business workspace.

Security in the workflow

Put careful boundaries where records can change hands.

These current OpenDog views use sample grooming data. They show review points in the product; they are not security certifications, penetration-test reports, or a promise that any internet service is risk-free.

Preview imports before saving

A CSV upload opens a review first so the owner can see ready, matched, duplicate, invalid, and skipped rows before records are added.

OpenDog import preview using sample client and dog rows, with ready and needs-attention outcomes before records are saved.

Keep card entry in the supported payment path

OpenDog keeps appointment-linked invoices, recorded payments, and balances visible while supported online card entry and processing stay with Stripe.

OpenDog invoice list using sample data, showing invoice totals, paid, sent, draft, and balance-due status without displaying complete card details.

Review business totals inside the account

Owner reports organize appointments, dogs, services, invoices, recorded payments, balances, deposits, tips, and exports without presenting processor data as an accounting or security audit.

OpenDog owner reports using sample data, showing operational and payment totals available inside the business account.

Start with an honest security boundary.

OpenDog is a web application for operating a grooming business. Security controls reduce risk; they do not make a device, employee, password, payment account, imported file, or internet connection impossible to compromise. OpenDog does not claim SOC 2, HIPAA, PCI certification, end-to-end encryption, or any other independent certification on this page.

  • Use only the records the business is authorized to keep.
  • Give each person their own account and the least access needed for the job.
  • Keep computers and phones updated, locked, and out of shared personal accounts.
  • Report suspected unauthorized access promptly and preserve useful details.

Protect sign-in, passwords, and recovery.

OpenDog stores passwords as one-way hashes using the application platform’s current password-hashing default. Sign-in checks the stored hash, limits repeated failed attempts, and regenerates the browser session identifier after a successful login. Password-reset and staff-invitation links use time-limited, one-use token records rather than sending a password by email.

  • Use a unique password that is not shared with email, payment, or social accounts.
  • Keep the account email current and protect that inbox with its own strong sign-in controls.
  • Never send passwords, reset links, or invitation links in an ordinary client note or import file.
  • Change the password and review active devices when an account may have been exposed.
Open the OpenDog Login Page

See and close signed-in sessions.

An authenticated user can review current signed-in devices, see a device label, last-active time, and masked network context, then sign out another device or all other devices. Sessions close after two hours without activity and after 14 days overall. Changing a password signs out other sessions.

  • Review the device list after staff, phone, or computer changes.
  • Sign out an unfamiliar or retired device immediately.
  • Do not leave a shared front-desk or van device signed in for the next person.
  • A network label is supporting context-not proof of who used the device.

Keep browser sessions and form changes guarded.

Production HTTPS responses set HSTS and common browser-safety headers. On HTTPS, the OpenDog session cookie is marked Secure, HttpOnly, and SameSite=Lax. State-changing account and business forms use session-bound request tokens so a valid browser session must also present the expected form token.

  • Use the https://opendogos.com address and do not ignore browser certificate warnings.
  • HttpOnly keeps normal page scripts from reading the session cookie; it does not make an unlocked device safe.
  • SameSite and request tokens reduce cross-site request risk; they do not replace careful access decisions.
  • Security headers add browser boundaries without claiming every browser or extension is trustworthy.

Separate staff work by role and shop.

OpenDog carries the signed-in user’s role and shop account through protected workflows. Controllers check authentication and allowed roles before restricted actions. Customer, dog, appointment, service, route, payment, report, and other business queries are scoped to the active shop account, and platform-administration paths use a separate platform-admin check.

  • Review manager, staff, and groomer access before sending an invitation.
  • Deactivate access when a person leaves or no longer needs the workspace.
  • Test each real role on the pages and actions it should-and should not-use.
  • Shop scoping is an application control; businesses still need clean user ownership and offboarding.

Keep public requests outside the staff workspace.

Hosted request pages are customer-facing paths, not shortcuts into admin screens. A request collects service details for review and remains separate from a confirmed appointment until the business accepts the work. Owners should publish only the fields, services, policies, and contact details clients truly need.

  • Do not ask clients to place passwords, full card details, or unnecessary private information in request notes.
  • Review the dog, address, service, timing, and route fit before confirming.
  • Keep internal staff notes and private operating details out of public page copy.
  • Treat every submitted note as client-provided information that still needs human review.
See Booking Request Review

Review files before importing business records.

CSV import is available inside an authenticated business account and opens a preview before save. The preview distinguishes new, matched, duplicate, invalid, and skipped rows. Import runs record outcome totals, and supported newly inserted records may be undoable when later activity has not made reversal unsafe.

  • Move only the columns needed for the grooming workflow.
  • Never place complete card numbers, security codes, passwords, private message archives, or unrelated personal information in a CSV.
  • Use a small representative sample and verify the working records after import.
  • Restrict temporary files and remove copies according to the business’s own retention policy.
Review OpenDog Data Import

Keep card handling with Stripe.

Supported online payments use Stripe-hosted or Stripe-controlled card-entry flows after the business completes the required setup. OpenDog stores the invoice, appointment, amount, status, and provider references needed to follow the payment workflow; it does not ask staff to type complete card numbers or security codes into ordinary OpenDog records. Incoming Stripe payment events must pass signature verification before payment updates are applied.

  • Complete Stripe onboarding through the supported account path.
  • Never collect complete card details in notes, email, text, support messages, or CSV files.
  • Limit manual saved-card actions to authorized roles and the supported approval flow.
  • Review receipts, balances, refunds, disputes, and payout questions against the Stripe account as well as OpenDog.
See Invoices and Payments

Use audit history for the actions it actually records.

OpenDog records audit events for selected account, staff, website, payment, billing, import, and platform operations. The available history can help explain who performed a supported action and when. It is not a complete recording of every click, screen view, conversation, or event outside OpenDog.

  • Confirm which high-impact actions appear in the account before relying on them.
  • Keep staff identities individual so recorded actions remain meaningful.
  • Reconcile provider activity separately when Stripe, email, maps, or another connected service is involved.
  • Preserve relevant exports, receipts, and support correspondence when investigating an incident.

Run a practical security check before launch.

Use a sample shop and the real devices the team will carry. Prove sign-in, role limits, session review, a public request, a small import, a payment handoff, an export, staff removal, and recovery before the live calendar depends on the account.

  • Owner, manager, staff, and groomer can reach only the workflows they need.
  • A public visitor cannot open an authenticated business area.
  • An imported dog stays with the correct owner and shop.
  • A card is entered only in the supported Stripe path.
  • A lost or retired device can be signed out and a former team member can be deactivated.
  • The owner knows who to contact and what details to gather when something looks wrong.
Bring Security Questions to Support

Workflow

Know who owns each part of the boundary.

OpenDog owns…

The application controls described here: authenticated routes, role checks, shop scoping, session handling, request tokens, supported import review, Stripe-event verification, and selected audit history.

Your business owns…

Unique accounts, strong credentials, staff access, device security, lawful records, public form choices, file handling, payment policy, offboarding, and prompt incident reporting.

Connected providers own…

Their accounts, infrastructure, approvals, card processing, message delivery, maps, payouts, disputes, and provider-specific security or availability commitments.

FAQ

Common questions from grooming businesses.

What security controls does OpenDog use today?

OpenDog uses authenticated application routes, role checks, shop-scoped data access, one-way password hashing, failed-login limits, revocable sessions, session-bound form tokens, HTTPS response protections, reviewed imports, Stripe signature verification, and audit history for selected operations. Each control has limits, and no internet service can promise zero risk.

Can I see and sign out other OpenDog sessions?

Yes. The account security page lists active signed-in devices with last-active and masked network context. You can sign out another device or all other devices. Sessions also close after two hours without activity and after 14 days overall.

Can every staff member see every business area?

No. OpenDog checks authenticated roles before restricted workflows, and platform-administration paths require a separate platform-admin check. Owners should still test the exact manager, staff, and groomer access they plan to use and deactivate people who no longer need the account.

Does OpenDog store complete card numbers or security codes?

Supported online card entry and processing use Stripe-hosted or Stripe-controlled flows. OpenDog keeps the appointment, invoice, amount, status, and provider references needed for the workflow; staff should never put complete card numbers or security codes in OpenDog notes, CSV files, email, text, or support messages.

Is OpenDog SOC 2, HIPAA, or PCI certified?

OpenDog does not claim SOC 2, HIPAA, PCI certification, end-to-end encryption, or another independent certification on this page. Ask support about any specific contractual, regulatory, insurance, or vendor-review requirement before relying on OpenDog for it.

What should I do if I suspect unauthorized access?

Use the account security page to sign out other devices, change the password, protect the account email, deactivate affected staff access when appropriate, preserve useful dates and details, review connected-provider activity, and contact OpenDog support promptly.

Bring the exact security question-not a generic checklist.

Tell us the roles, devices, records, imports, public pages, payment flows, and provider requirements your grooming business expects to use. We will answer against the controls that exist today and call out what still belongs to your team or another provider.