Home / Security

Data security

How Maha Hub protects hotel and guest data: our principles, safeguards, providers and commitments.

Last updated: 8 October 2026

Summary

Our commitment. Maha Hub is built so that each hotel's data is reachable only by the people that hotel authorises, travels over encrypted connections, and is handled by a small set of named infrastructure providers.

  • Every Maha product is opened for a hotel individually by Padauk. Nothing is switched on by default.
  • Access inside a hotel is controlled by user roles and staff shifts.
  • Card payments are handled by Stripe. Maha Hub never receives or stores full card numbers.
  • We do not claim certifications we do not hold.

Security principles

Our approach to security rests on five principles that guide how Maha is designed, operated and supported:

  • Least privilege. People and systems receive only the access they need for their role, and no more.
  • Separation by hotel and by product. Each hotel's workspace and each Maha product are opened separately, so access to one does not grant access to another.
  • Encryption in transit. Maha Hub and its products are served only over HTTPS, so data moving between your device and Maha is encrypted.
  • Accountability. Each user signs in with their own account, and front desk work is tied to a named shift.
  • Transparency. We describe our safeguards accurately and tell customers what we do, and do not, provide.

Access control

  • Individual accounts. Every user signs in with their own credentials. Shared logins should not be used.
  • Role-based permissions. Roles such as manager, front desk and housekeeping limit what each user can see and change.
  • Shift-based sign-in. Front desk users sign in to a named shift, linking transactions and cash handling to the right person and time.
  • Product activation. Maha Connect, Maha Booking and Maha Reach are opened per hotel by Padauk on request, keeping each hotel's footprint to what it actually uses.
  • Prompt removal. Customers can remove users at any time, and should do so as soon as a staff member leaves.

Infrastructure and providers

Maha Hub runs on established cloud infrastructure and uses a small number of specialist providers, each bound by its own security and privacy commitments:

  • Cloudflare for hosting, content delivery and network protection of the Maha Hub website and applications.
  • Stripe for payment processing. Payment details are entered directly with Stripe, which is responsible for protecting card data.
  • A cloud database for storing customer business data used to provide the service.

We review providers before adopting them and keep the list as short as the service allows.

Payments

Subscription payments and any card payments made through Maha are processed by Stripe. Maha Hub does not receive, store or have access to full payment card numbers or security codes. Staff must never enter card numbers into notes, messages or free-text fields in Maha.

Shared responsibility

Security works best as a partnership. Maha Hub is responsible for the security of the service. Each customer is responsible for how the service is used within its hotel, including:

  • choosing strong passwords and keeping them private;
  • assigning the right role to each user and reviewing access regularly;
  • removing access for staff who leave;
  • keeping the devices used to access Maha secure and up to date;
  • entering only the guest and staff information it is entitled to collect.

Incident response

If we become aware of a security incident affecting customer data, we will investigate promptly, take steps to contain it, and notify affected customers without undue delay with the information we have at the time. Where the law requires us to notify a regulator or affected individuals, we will do so within the required period, or support the customer in doing so where the customer is responsible for that notice.

Certifications and compliance

Maha Hub does not currently hold formal security certifications such as ISO 27001 or SOC 2, and is not itself certified under PCI DSS. Card payments are handled by Stripe, which maintains its own payment card compliance. We will only list certifications on this page once they have been formally obtained.

Maha is designed to help hotels meet their own obligations under data protection laws such as Thailand's Personal Data Protection Act, by keeping guest data organised, access-controlled and limited to authorised users.

Reporting a vulnerability

We welcome reports from anyone who believes they have found a security weakness in Maha Hub. Please email support@maha-hub.com with a clear description and the steps to reproduce it.

When testing, please act in good faith: do not access, change or delete data that is not yours, do not disrupt the service for others, and give us reasonable time to fix the issue before sharing it publicly. We will acknowledge genuine reports and keep you informed of our progress.

Banner image: wall painting at Upali Thein, Bagan, a UNESCO World Heritage Site. Photo by Anandajoti Bhikkhu (photodharma.net), CC BY-SA 3.0.