AuthenticationIndustry-standard token-based authentication. Sessions are scoped and time-limited.
Data in TransitAll data transmitted over HTTPS/TLS. No unencrypted channels.
Access ControlRole-based access control. Admin, user, and creator roles with strict permission enforcement.
Webhook VerificationAll incoming Stripe webhooks are cryptographically verified using HMAC-SHA256 signatures.
Internal API SecurityInternal server-to-server calls use signed tokens. No secrets are passed through request bodies or frontend code.
Data CollectionWe collect only data necessary to operate the platform: account information, device registration details, and transaction history.
Data RetentionUser data is retained for the duration of the account relationship. See our Privacy Policy for deletion rights.
Third-Party SharingWe do not sell personal data. Data is shared only with service providers required to operate the platform (Stripe for payments, Shippo for shipping).
GDPRUsers have the right to access, correct, and delete their personal data. Contact support to exercise these rights.
AnalyticsAggregate analytics are collected to improve platform performance. Individual user behavior is not sold or used for advertising.
Cloud HostingPlatform is hosted on managed cloud infrastructure with automated failover and redundancy.
Data IsolationEach tenant's data is logically isolated. Row-level security is enforced at the database layer.
BackupsAutomated database backups are performed regularly. Recovery procedures are tested periodically.
UptimeWe target high availability. For enterprise SLA commitments, contact our sales team.
Support AvailabilitySupport is available via our support center. Response times vary by plan.
Incident ResponseSecurity incidents are investigated promptly. Affected users are notified in accordance with applicable law.
ContactFor security concerns or data requests, reach us through the support center.
This page reflects our current platform practices. Last reviewed April 2026.