Security

Last updated October 2026

How we protect your store and your customers' data.

Data isolation

Every store's data is separated at the database level with row-level security, so one merchant cannot read another's data.

Secrets and credentials

Payment and API credentials are kept on the server and are never sent to the browser. Passwords are stored using strong one-way hashing.

Encryption and hosting

Traffic is encrypted with HTTPS. We use managed, reputable infrastructure providers for hosting and the database, with regular backups.

Access control

Staff accounts have roles (owner, admin, staff) that limit what they can change. Super-admin access to the platform is restricted.

Reporting a vulnerability

If you believe you have found a security issue, email legal@serafox.com with details. Please give us reasonable time to fix it before disclosing it publicly.

This document is provided for information and does not replace advice from a qualified lawyer about your own obligations.