Security & Privacy
Your data security is our top priority. Learn about the measures we take to protect your information.
Security Measures
Data Encryption
All sensitive data is encrypted using AES-256 encryption at rest
- Email addresses
- Phone numbers
- Payment identifiers
- Authentication secrets
Row-Level Security
Database policies ensure users can only access their own data
- 97 security policies
- 24 protected tables
- Role-based access control
Two-Factor Authentication
Optional TOTP-based 2FA for enhanced account security
- Authenticator app support
- Encrypted backup codes
- Rate-limited verification
API Protection
All endpoints are protected with rate limiting and validation
- 21 secured endpoints
- Input validation
- Request throttling
Audit Logging
Comprehensive logging of security-relevant actions
- Immutable audit trail
- Admin action tracking
- 90-day retention
Access Control
Granular permissions based on user roles
- User, Shop Owner, Admin roles
- Principle of least privilege
- No anonymous access to sensitive data
Your Data Rights
GDPR Compliance
We respect your privacy rights and make it easy to exercise them
Data Export
Export all your personal data anytime
Data Deletion
Request complete account deletion with 24-hour grace period
Data Portability
Receive data in standard JSON format
Consent Management
Control how your data is used
Security at a Glance
Security Compliance Report
Download a comprehensive security compliance report documenting all security measures in place
Reports include: RLS policies, encryption details, rate limiting, GDPR compliance, and audit logging configuration.
Questions About Security?
If you have any security concerns or want to report a vulnerability, please contact us.
Security issues are taken seriously and addressed promptly.