Back to home

Trust

Security

How we protect your data and the stores you build: encryption, isolation, infrastructure, and how to report a vulnerability.

Last updated: July 16, 2026

On this page

Encryption of sensitive data

The integration secrets you entrust to us — Shopify tokens, WooCommerce keys, InPost tokens, API keys for mailing providers (MailerLite, Mailchimp, Brevo) and form-webhook signing secrets — are encrypted at rest with AES-256-GCM, with the master key derived via scrypt.

Form submission privacy

IP addresses recorded with store form submissions are hashed with SHA-256, so we can detect abuse without storing raw addresses.

Encryption in transit and build isolation

All traffic is encrypted with TLS. Store builds run in an isolated pool of child processes, so one build cannot interfere with another or with the platform.

Infrastructure and backups

We run on servers located in the European Union (Hetzner, Germany). We maintain database backups so data can be recovered after an incident.

Subprocessors and data processing

Who we share data with and how we process it is covered on the Subprocessors page and in our Data Processing Agreement.

Still have a question?

If anything here is unclear, we would rather explain it than leave you guessing.

Contact us