ENCRYPTION
PASSlibsodium AEAD for tokens
All Shopify access tokens and Google Merchant Center OAuth tokens are encrypted at rest via libsodium AEAD (XChaCha20-Poly1305). Never plaintext in the database.
How we protect your store data, what we actually store, and our SOC 2 roadmap.
ENCRYPTION
PASSAll Shopify access tokens and Google Merchant Center OAuth tokens are encrypted at rest via libsodium AEAD (XChaCha20-Poly1305). Never plaintext in the database.
TLS
PASSTLS 1.3 on embedded admin, API, and landing, with HSTS enabled. Certificates provisioned by Infomaniak (Let's Encrypt automated).
GDPR
PASScustomers/data_request, customers/redact, and shop/redact implemented and tested. 48h grace window after shop/redact to allow accidental-redact recovery.
AUDIT
PASSEvery state mutation (product change, correction push, reinstatement request) is recorded in an append-only audit log accessible from the admin.
SOC2
WARNINGNot audited yet, and we will not claim otherwise. Encryption at rest, access control and append-only audit logging are in place today; the formal audit follows once our volume justifies its cost. We will publish the report here when there is one.
PII
PASSWe don't store any of your store customers' personal data - only encrypted access tokens and scan metadata. Compliance applies to merchant data, not the end shopper.
Sub-processors
| Service | Purpose | Region |
|---|---|---|
| Shopify | Store platform - the merchant data we read and write | US + global |
| Infomaniak | Application hosting + database + email | Switzerland |
| Cloudflare R2 | Blob storage (Reinstatement Report PDFs, scan reports) | EU + global CDN |
| Postmark | Transactional email + newsletters | US (DPA EU+US) |
| Anthropic | AI models (Sonnet, Opus) for feed rewrites and concise narratives | US |
| Google (Merchant API, Ads API) | Merchant Center and Google Ads integration | US + global |
| Stripe (P2) | Payments for one-time products (upcoming) | US (DPA EU+US) |
This list is updated before a new sub-processor begins processing.