Trust & data access

How Organize handles your studio's information

Organize holds your bookings, clients, rates, invoices and payment records. Before you put that into any software, you should know who can see it. This page answers that in plain language, and only says what the product actually does. The formal versions are on our Security and Privacy pages.

The short version

Can another studio see our data?

No. Every request is scoped to the signed-in user's studio, so another customer cannot use Organize to reach your records.

Can everyone in our studio see invoices and rates?

No. Financial screens and rate fields are limited to the roles you give financial access to.

Can Organize staff technically access our data?

Yes, with privileged infrastructure access, used only to operate, secure and support the service. Organize is not a zero-knowledge system.

Is Organize SOC 2 or ISO 27001 certified?

No. We don't claim certifications we don't hold. Our hosting providers hold their own.

1

Your studio data stays separated

Each Organize studio operates within its own account space. Every record — a booking, a client, a project, an invoice — belongs to exactly one studio. When you sign in, your session carries your studio's identifier, and the application filters every read and write by it.

In practice this means one customer cannot use Organize to browse another customer's projects, bookings, clients or financial records. If someone pastes in the ID of a record from another studio, the application answers “not found”. Links between records (a booking's room, artist and project, for example) are checked against your studio before they are saved.

To be precise about what this is: it is application-level isolation. Studios share the same infrastructure and database, and are kept apart by the application's own scoping rules, not by separate databases or per-customer encryption keys. That is the normal design for software of this kind; we just prefer to say it plainly.

More detail: How Organize keeps one studio's data separate from another →

2

Financial information is permission-controlled

A colourist or coordinator needs the schedule and the project. They usually do not need to see what the client is being charged. Organize separates the two: every user has a role, and only some roles can see money.

Financial access covers invoices, challans, quotations, recorded payments, the billing dashboard, room and artist hourly rates, and project rates. Users without it can still book rooms and artists, see projects and clients, and record session hours; the rate and billing fields are simply left out of what they see.

Can see financial information

  • Owner
  • Administrator
  • Accountant
  • Line Producer
  • Finance
  • Manager

Operational access only

  • Studio Coordinator
  • Staff
  • User
  • Viewer

Viewer is read-only across scheduling and projects, and still excluded from financial screens.

Within the financial roles, what each one can do also differs: for example, recording a payment against an invoice is limited to Owner, Administrator, Accountant and Finance, and only an owner can grant the Owner role. Overriding a booking conflict is a separate permission that, by default, only owners and administrators hold, and it always requires a written reason.

Why this matters in a post house: Who should be able to see financial information? →

3

Who at Organize can access customer data?

This is the question most software companies answer vaguely. Three different groups are involved, and they are not the same:

Normal application users

People in your studio, with the roles you gave them. They see your studio's data and nothing else.

Users from another studio

Nothing. Their sessions are scoped to their own studio, exactly as yours is scoped to yours.

Authorized Organize operations access

The small team that runs Organize has privileged access to the hosting account and database. With that access it is technically possible to read stored customer data. We use it only where it is needed to operate, secure or support the service, or where the law requires it.

We won't tell you Organize can never see your data, because for a managed service like this it would not be true. What we can tell you is how that access is used, and that our Terms commit us to accessing Customer Data only as necessary to provide the service or as required by law.

4

Activity and accountability

Organize keeps an activity log of the actions that matter to a studio: bookings created, edited and changed in status; conflict checks and overrides, with the reason given; challans and invoices created and moved between statuses; payments recorded; and user sign-ins. Each entry records which user acted and when, and your team can see your studio's entries in the Activity view.

This log covers actions taken through the Organize application. It does not record direct access to the database or hosting infrastructure by Organize staff or by our providers — we would rather say that here than let you assume otherwise.

5

Payments

Two different kinds of money show up in Organize, and it is worth separating them.

Your subscription to Organizeis paid through Razorpay (for studios billed in India) or Stripe (elsewhere). Card details are entered on the payment provider's own checkout and never pass through Organize; we store the plan, amount, date and the provider's transaction reference. Organize is not itself PCI certified; card handling is delegated to those providers.

Your clients' payments to youare recorded in Organize, not processed by it. When a client pays an invoice, someone with payment access records the amount, date and reference against that invoice. Organize does not move that money or hold your clients' card or bank details.

6

What Organize does not claim

We prefer specific claims we can support over badges we don't have. So, to be clear, Organize does not currently claim SOC 2 or ISO 27001 certification, an independent penetration-test certificate, multi-factor authentication for customer accounts, zero-knowledge encryption, or per-customer encryption keys.

What you do get is encrypted connections (HTTPS with HSTS), hashed passwords, signed sessions in HTTP-only cookies, studio-scoped data access, role-based financial visibility, an application activity log, and hosting on managed providers (Vercel and Neon) that encrypt stored data as part of their platforms. Each of those is described on the Security page with the same care.

How we got here: Why we removed security claims we couldn't prove →

7

If you leave

Your data is yours. If you close your studio account, we delete the studio's data within thirty days, keeping only what tax and accounting law requires us to keep. You can ask for an export of your data before that. Both are handled by the Organize team on request rather than by a self-service button at this stage, and we say so rather than imply otherwise.

Questions

If your IT or finance team has a question this page doesn't answer, email admin@organizeapp.org. Before you buy anything, our buyer's checklist lists what to ask any studio-management vendor, including us.

Start free

Your studio account is isolated from other Organize customers, with financial access controlled by role.

See also: Security · Privacy · Billing · Scheduling · Pricing