Trust Center

Security & Privacy at TurnKey

This page is maintained by the TurnKey team to answer common security and privacy questions about TurnKey CRM. It describes controls that are enabled in the product today. It is editable project content, not an independent audit or certification.

Access & authentication

  • Email + password sign-in, with optional Google sign-in.
  • Optional two-factor authentication (TOTP) with recovery codes.
  • Role-based access: owner, office, field crew, vendor, and customer portal — each scoped to their own data.
  • Row-level security on every tenant table, so one company's data is never visible to another.
  • Sensitive property credentials (gate codes, lockbox codes) are read through audited server-side functions and are not exposed on regular table reads.

Hosting & infrastructure

  • The application runs on Lovable Cloud, which uses Supabase for the database, authentication, storage, and serverless functions.
  • Traffic is served over HTTPS/TLS in transit. Data at rest is stored in the managed Postgres database provided by the platform.
  • Backups, patching, and platform-level hardening are handled by the underlying hosting provider.

Platform features described here are provided by the hosting platform. Listing them here is not a certification by Lovable or by any third party.

Data we collect & how it is used

  • Account info for staff and crews (name, email, phone, role).
  • Customer and property records, jobs, estimates, invoices, photos, and notes that you enter into the system.
  • Operational data created by use of the app: time clock punches, GPS location while on-shift, job events, and SMS/email logs related to your jobs.
  • We use this data only to operate TurnKey for your business. We do not sell customer data.

Subprocessors & integrations

TurnKey relies on a small set of trusted vendors to deliver core functionality. Integrations are only enabled when you configure them.

  • Hosting, database, auth, storage: Lovable Cloud (Supabase).
  • Payments (optional): Stripe.
  • Email (optional): Resend.
  • SMS / voice (optional): Twilio.
  • AI features (optional): Lovable AI Gateway.

Storage & file uploads

  • Photo, document, and receipt uploads are stored in tenant-scoped buckets.
  • Crew receipt uploads are scoped to the uploader's own folder under their tenant; office roles can review receipts for their tenant.
  • Client submission packages for property preservation are stored in a private bucket and shared only via short-lived signed URLs.

Retention & deletion

Your business data is retained while your account is active. Customer-facing records can be edited or removed by office roles from inside the app. If your company stops using TurnKey, contact us to request deletion of your tenant's data.

Privacy requests

If an end customer asks your business to access, correct, or delete their record, your office team can do so from the customer detail screen. If you need help fulfilling a privacy request, contact us using the security contact below.

Reporting a security concern

If you believe you have found a vulnerability or have a security question, email security@turnkeycrm.app. Please include steps to reproduce and any relevant URLs. We will acknowledge reports within a reasonable timeframe and keep you informed as we investigate.

Shared responsibility

TurnKey provides the controls described above. Your business is responsible for managing user invitations, assigning roles correctly, keeping sign-in credentials safe, and using two-factor authentication for office and admin accounts. End customers are responsible for safeguarding any portal links shared with them.

Last updated: 9/8/2026. This page is editable project content maintained by the TurnKey team and does not constitute legal advice, certification, or a warranty.