A business-management system can hold some of the information a company depends on most: customer contact details, conversation notes, documents, active work, invoices and payment records.
It is reasonable to ask what happens behind the simple screens used each day. Who can see the information? Can somebody bypass the visible controls? What happens when a team member should no longer have access?
Waypoint is designed so privacy and security are part of the product’s foundations rather than optional extras reserved for a more expensive subscription.
The protections described here are those implemented in the current platform. They are explained in practical terms because a business owner should not need to become a security specialist to understand how their information is handled.
Your workspace is kept separate

Each business in Waypoint operates inside its own workspace. Customer records, prospects, work, documents, tickets, invoices and payments are stored with the identity of the workspace they belong to.
The platform checks that identity when information is requested. These checks are designed to prevent a user in one business from requesting records belonging to another business, including attempts made outside the normal interface.
What this means for you: signing in to Waypoint should take you to your business information, not a shared pool of everybody’s records. Changing an address or record identifier manually should not provide a route into another workspace.
Roles decide what each person can do
People within the same business do not always need the same access. Waypoint uses roles and permissions to determine which areas and actions are available to each team member.
Owners and administrators can manage more of the workspace. Managers, members and read-only users receive access appropriate to their role, with additional record-level restrictions where they apply.
What this means for you: a person can be given enough access to complete their responsibilities without automatically receiving every administrative or financial capability in the business.
Permissions apply behind the screen
Hiding a button is not security. Waypoint uses the permission information returned to the interface to keep screens clear, but the server remains authoritative.
When somebody requests protected information or attempts an action, the server checks their workspace, enabled features, role and effective permission. A request is refused when the required access is missing, even if it did not come through the visible button or navigation link.
What this means for you: security does not depend only on what a user can see in their browser. The same permission rules are applied where the action is actually processed.
Access can be withdrawn from an existing session
Suspending access, changing a role or resetting credentials should not leave an older signed-in session trusted indefinitely.
Waypoint changes the user’s authentication version when these important account events occur. An existing session carrying the older version is rejected and the person must authenticate again where access remains permitted. Archived or removed accounts can no longer resolve a valid session.
What this means for you: access changes take effect behind the screen as well as in the user list. An older browser session does not simply retain the permissions it had before the change.
Security Activity provides accountability
Waypoint has a workspace Security Activity record for important access and permission events that are implemented today. These include role changes, access suspension and restoration, password resets, invitations and permission denials.
The record is kept separately from operational histories such as invoice payments. Viewing Security Activity itself requires the relevant permission, and the records do not store passwords or authentication tokens.
What this means for you: authorised people can review important security-administration events without sensitive credentials being copied into the activity history.
This is a focused security record, not a claim that every click or change anywhere in Waypoint is currently recorded in one universal audit trail.
Turning a feature off also closes its protected actions
A workspace can enable the business areas it needs and disable those it does not. The visible navigation updates, but the control does not stop there.
The server includes the current feature configuration when it calculates effective permissions. A capability linked to a disabled feature becomes ineffective, and direct requests to its protected actions remain unavailable.
What this means for you: switching off a feature does not merely remove its menu item while leaving the underlying action open.
Unexpected requests are handled deliberately
Online services receive requests that are incomplete, malformed or different from what the normal interface would send. Waypoint validates request types, identifiers and submitted values before acting on them.
Known validation, permission and authentication failures are returned in a controlled form. Unexpected server errors use a general response rather than deliberately returning internal error details to the requester.
What this means for you: a bad request should fail safely and explain only what is useful, without unnecessarily exposing the platform’s internal workings.
Permanent deletion is separated from ordinary workspace access
Archiving a user or record is a normal reversible business action. Permanently deleting an entire business is deliberately different.
Ordinary workspace roles cannot perform platform-administration actions. The permanent-deletion workflow is reserved for platform administrators and requires a server-generated impact review, fresh confirmation and separate production safeguards. The platform-owner workspace is protected from the standard deletion workflow.
Production deletion remains unavailable unless its required retention and independently secured deletion-ledger settings are configured. This avoids presenting a destructive control before the surrounding recovery and governance arrangements are ready.
What this means for you: broad day-to-day workspace permissions do not silently include the ability to erase an entire business. Permanent deletion is kept behind a distinct and more tightly controlled process.
Waypoint aims to collect what the service needs
Privacy begins with limiting unnecessary collection. Waypoint uses business and account information to provide the requested service, keep records connected, respond to enquiries and protect the platform.
The public website currently has no advertising trackers, behavioural advertising or third-party analytics service. Enquiry information is not used for automated decision-making or profiling, and personal information is not sold.
What this means for you: visiting the public site is not used to build an advertising profile, and information submitted through the contact form is collected for handling that enquiry and the related business purpose.
The published Privacy Notice currently covers the public website, contact enquiries and early-access requests. If an enquiry becomes access to the Waypoint application or a customer relationship, additional contractual and privacy information may apply.
External services have limited jobs
Waypoint uses selected service providers where they are needed to operate the service.
Cloudflare supports the public website through hosting, content delivery, DNS, server-side form handling and short-lived rate limiting. The application also uses a private Cloudflare R2 bucket for document storage. Stored files are delivered through authenticated Waypoint routes after workspace and record-access checks rather than through public bucket links.
Resend is used by the public website to deliver contact-form emails. It receives the information needed to deliver that enquiry; it is not an advertising or behavioural-analytics service and is not used to inspect Waypoint workspace records.
What this means for you: these providers perform specific operational jobs. Their presence is disclosed in the Privacy Notice rather than being hidden behind a general statement about unnamed partners.
The Privacy Notice explains your choices and rights
Waypoint’s public Privacy Notice explains the controller responsible for the information, the categories collected, purposes and lawful bases, service providers, international transfers, normal enquiry retention, individual rights, security measures and how to make a complaint.
It includes a route for contacting Waypoint about privacy and explains that a person may also complain to the UK Information Commissioner’s Office.
What this means for you: the practical summary in this article is not a replacement for the formal notice. The notice provides the fuller information needed to understand the public website and enquiry process.
Built around demanding UK privacy expectations
Waypoint is being developed around UK privacy and data-protection expectations. That creates a strong foundation for handling business information carefully and for supporting customers elsewhere.
It does not automatically make Waypoint—or a business using it—legally compliant in every country or industry. Data residency, consent, contractual, tax, regulatory and retention requirements can differ by location and type of work.
What this means for you: Waypoint provides product safeguards, but each business remains responsible for understanding the legal and professional obligations that apply to its own activities.
Security is continuing work, not a finished badge
No responsible online service can promise complete invulnerability. Claims such as “unhackable” or “guaranteed protection” would not be realistic.
Privacy and security require ongoing testing, review and improvement as the platform changes and potential threats develop. Waypoint maintains focused automated checks for workspace separation, permissions, feature enforcement, session invalidation, request handling and deletion safeguards, alongside continued engineering review.
What this means for you: the current controls are real and tested, but they are not treated as a reason to stop improving the service or to make blanket compliance promises.
Protection is part of the product
You can also review the everyday business areas included across Waypoint.
Workspace separation, server permission checks, session controls and safe request handling are not premium upgrades. They protect the way the platform operates regardless of which business features a workspace chooses to use.
Business owners should be able to concentrate on their customers and their work without needing to become security specialists.
Waypoint’s responsibility is to make strong privacy and security controls part of the everyday platform—not an afterthought or an expensive extra.
Frequently asked questions
Can another Waypoint business see my workspace records?
Waypoint applies workspace-isolation checks at the server and data-access layers. These are designed to prevent one business from requesting another business’s customers, work, documents or financial records.
Are permissions enforced only by hiding buttons?
No. The interface reflects the user’s permissions, but the server checks the current workspace, enabled features and effective capability before protected requests are processed.
What happens after a user is suspended or their role changes?
The account’s authentication version changes. Existing sessions carrying the older version are rejected, so previous access does not simply continue in an already-open browser.
Does Waypoint record security activity?
Yes, for the security events implemented in the current ledger, including role and access changes, password resets, invitations and permission denials. This is a focused security record rather than a universal log of every action.
Does the public website use advertising trackers?
No. The verified current website does not include an advertising tracker or third-party behavioural analytics service.
What are Cloudflare and Resend used for?
Cloudflare supports website delivery, server-side contact handling, rate limiting and private application document storage. Resend delivers emails submitted through the public contact form.
Is Waypoint completely secure?
No online service can responsibly promise complete invulnerability. Waypoint uses implemented and tested controls while continuing to review and improve privacy and security as the platform develops.
Does using Waypoint make my business legally compliant everywhere?
No. Waypoint is developed around demanding UK privacy expectations, but legal, regulatory, residency and retention requirements vary between countries, industries and businesses.
