How we protect your store and your customers' data.
Data isolation
Every store's data is separated at the database level with row-level security, so one merchant cannot read another's data.
Secrets and credentials
Payment and API credentials are kept on the server and are never sent to the browser. Passwords are stored using strong one-way hashing.
Encryption and hosting
Traffic is encrypted with HTTPS. We use managed, reputable infrastructure providers for hosting and the database, with regular backups.
Access control
Staff accounts have roles (owner, admin, staff) that limit what they can change. Super-admin access to the platform is restricted.
Reporting a vulnerability
If you believe you have found a security issue, email legal@serafox.com with details. Please give us reasonable time to fix it before disclosing it publicly.
This document is provided for information and does not replace advice from a qualified lawyer about your own obligations.