Trust and security

Built to
be audited.

Somebody hands a stranger a key and a card. Here is what happens to both.

Their carTheir cardSession 214one record,and it keeps both

Where the card goes

The number
never reaches us.

Card details go from the guest's own browser, or from the tap on the valet's phone, straight to Stripe. Valletto's servers are not on that path, so there is nothing on them to take.

Your company receives its guest payments through its payment account. Review the applicable processing fees and payout terms during setup.

Guest or valetBrowser, or a tapStripeThe processorVallettoNot on the pathCard number, CVV, the whole credentialAmount, brand, receiptstraight past us,on purpose
What we keep for a card payment×
$18.00
VisaThe brand. Never the number.
$4.00 tipReceipt, stand and time of day
Stand 2 · 6:52 PMCard, in person, on the operator's account
The credential stays with the processor

Both ends of a session

What the handover
writes down.

The car is photographed at check-in and its plate is read and kept as an image. Every status after that carries a name and a time: received, parked, requested, retrieved, paid.

Two more are per-location settings the operator turns on: an odometer reading in and out, with a mileage alert threshold, and a damage inspection that has to be completed before the car is allowed to move.

CHECK-IN4RJ K812Odometer in 41,208Damage check · clear6:40 PM · Marco RuizCHECK-OUTOdometer out 41,213+5 miles · under threshold9:14 PM · Elena CruzPaid · $18.00a name and a timeon every step

The record

A protected history
of the visit.

Your team can review the visit from check-in to handoff, with the people and times attached to the work. A clear history helps you answer questions without relying on someone's memory.

Correction · session 214Drop-off time6:40 PMMarco Ruiz · 7:02 PM6:12 PMGuest arrived earlier than loggedManagers at this location notifiedthe old valuenever disappears

When a time is wrong

An edit is an entry,
not a replacement.

Times do need correcting. A guest really did arrive earlier; a clock really was off. The server does not treat that as a privilege, it treats it as a record: the reason comes from a fixed list, the old and the new value both go into the session's log with the editor's name, and the managers at that location get a push.

A session that has already been paid refuses the edit outright, and a future timestamp is refused at the door.

Who can do what

Hiding a button
is not a permission.

Access follows each person's role in your company. Your team can see who may perform the actions below.

Access by role
Clear responsibilities
Protected account access

Personal profile changes do not change a team member's role or company access.

The door
Owner, admin
Manager
Supervisor
Valet
Clock a teammate in or outPunching anybody but yourself
Decide a time-off requestApproving or refusing an unavailability
Change the schedule's settingsPublishing rules, claim windows, notice periods
Change where the money settlesThe payment account a payout lands in
Dispute Evidence ReportCharge disputed 11:04 AM · report ready 11:04 AMHow the guest paidReceiptSession timelineVehicleSMS delivery logSupporting visit detailswritten beforeanyone asks for it

When a charge is disputed

The evidence
assembles itself.

A dispute lands from the card network and the report is generated on the spot, before anyone has been told. It pulls the charge, the session, that session's own event timeline, the messages the guest was sent, the car photographed at check-in and the device the payment came from, and brings the available visit details together for review.

What it does not do is guess. A fact that is missing has its sentence left out rather than filled in, and submitting the response to the network is still a decision a person makes.

Your IT team's list

Send us the long form.

Property IT, associations and procurement: we answer security questionnaires directly, and we would rather answer yours before you sign than after.