Your data stays your data
How to keep your shop's information and your customers' information safe when you start using AI

Your customer list is one of the most valuable things your shop owns. It's years of birthdays, anniversaries, wedding dates and sympathy orders. Before you hand any of it to an AI tool, you should know exactly where it goes and who can see it.
Here's the short version of how we think about it: your data stays your data. We use it to do the work you ask for. We never sell it. We never share one shop's information with another shop. And the partners who help us run the service only get what they need to do their part.
Don't paste your customer list into a free chatbot
This is the most common mistake we see. An owner copies a spreadsheet of names and phone numbers into a free consumer chat app and asks it to "write birthday texts."
The problem isn't the AI. It's the terms. Free consumer apps often have different privacy settings than business products, and some may use what you type to improve their models unless you turn that off. Your customers never agreed to that.
Do this instead: use a business service that tells you in plain words what it does with your data, who it shares it with, and how to delete it.
Ask who touches your data
No online service runs alone. Every AI tool relies on other companies for hosting, messaging and payments. That's normal. What matters is that the company tells you who they are.
Here's our list. It's also on our privacy page:
- Cloudflare hosts our website and the engine that runs your AI. Cloudflare has held a SOC 2 Type II report since 2019 and renews it every year.
- Stripe handles billing. We never see or store your card number.
- Anthropic provides the AI model that reads and writes your messages. Under Anthropic's commercial terms, it does not use business customers' inputs or outputs to train its models by default.
- HighLevel helps deliver customer messages. HighLevel completed a SOC 2 Type II audit in early 2026.
- Meta delivers WhatsApp messages when you choose to use WhatsApp.
If a vendor can't give you a list like this, that's a red flag.
What "SOC 2" and "SOC 3" mean, in plain English
You'll see these letters on a lot of security pages. Here's what they are.
A SOC 2 Type II report is an independent audit. An outside accounting firm checks a company's security controls and then watches them work over several months. "Type II" matters because it proves the controls work over time, not just on one day.
A SOC 3 report is the public summary of that same kind of audit. Anyone can read it. Stripe, for example, publishes its SOC 3 report openly.
One honest note: Gold Rose itself is a young company and does not hold its own SOC 2 report yet. What we do is build on partners that do, keep our own setup small, and tell you exactly how it works. Be wary of any small vendor that claims a certification without showing you the report.
How your card is protected
When you add a card, it goes straight to Stripe. It never touches our servers.
Stripe is certified as a PCI Service Provider Level 1, the strictest level in the payments industry. Stripe encrypts every card number with AES-256 and keeps the decryption keys on separate machines. Its card systems run in their own isolated environment, apart from the rest of Stripe's services.
What that means for you: there is no card number in our database to steal.
How your shop's information is kept separate
Every shop's information is kept apart from every other shop's. Your AI only ever sees your own customers, your own messages and your own notes. It can't see another florist's list, and another florist's AI can't see yours.
Everything travels over encrypted connections (the padlock in your browser). And every action your AI takes is written to a log you can check. Text it "what did you send today?" and it will tell you.
Your customers come first
The data you hold isn't only yours. It belongs to people who trusted your shop with their birthdays and their grief. A few rules we follow, and you should expect from any vendor:
- Collect only what's needed. Your AI doesn't need a customer's home address to send a birthday reminder.
- Text only people who agreed. Marketing messages go only to customers who opted in. Anyone can reply STOP.
- Delete when you leave. When you cancel, we delete your shop's customer data within 30 days unless you ask us to keep it or the law requires records.
Quick checklist before you sign up for any AI tool
- Do they list the companies that handle your data?
- Do they say, in writing, that they don't sell your data?
- Can you export your data and delete it whenever you want?
- Is your card handled by a PCI Level 1 processor, not stored by them?
- Does anything go to a customer without your OK?
- Can they show you a security report, or do they only use the words?
If the answer to any of these is "I'm not sure," ask before you upload a single name.
Questions about how we handle your data? Email [email protected] and a person will answer.


