Security
Your data is not our product.
We do not sell it, mine it, or stand between you and your customers’ money. What follows is the detail behind that sentence: where the data physically sits, who else touches it, what is encrypted, and what we have not certified yet.
Send us your vendor questionnaire · a person answers it, not a form letter
- Where platform data is stored
- EU
- On every connection
- TLS 1.3
- Named sub-processors
- 3
- Response to a data request
- 72h
Hetzner data centres, Germany
HSTS, one-year max-age, no HTTP fallback
Hetzner, Cloudflare, Stripe — listed below
Export or erasure, on request
Where the data lives
EU data centres, in Germany.
Platform data is stored in EU data centres on dedicated infrastructure operated by Hetzner Online GmbH. That is worth stating plainly, because for a European merchant it is usually the first question and the hardest one to get a straight answer to.
There is no on-premise or self-hosted edition. Every merchant runs on the same hosted platform — which is precisely why one set of controls can cover everyone.
Infrastructure is redundant and monitored continuously from the inside. You will not find an uptime figure quoted on this page: when we commit to one it will be in a contract, where it means something.
Infrastructure
- Hosted in EU data centers on dedicated infrastructure
- PostgreSQL with automated daily backups
- Redis-backed job queues for background processing
- Cloudflare for CDN, bot protection, and DDoS mitigation
- Private network between all internal services — no public service-to-service traffic
- Secrets managed via environment variables; never committed to version control
Controls
What is in place, and what is not.
Six controls, each with its real status. Anything still on the roadmap says so on the same line as the thing it belongs to, so nothing has to be read twice.
- Active
Encryption in transit
TLS 1.3 is enforced on every connection. HTTP Strict Transport Security is set with a one-year max-age, and there is no HTTP fallback.
- Active
Credential encryption
Sensitive credentials and secrets — API keys, integration tokens — are encrypted at the column level. Full-disk and backup encryption are on the hardening roadmap rather than in place today.
- Active
Access control
Internal access follows least-privilege principles, and platform-admin rights are an allowlist held in deployment configuration rather than a role anyone can grant from inside the app. Your own team’s actions — product and stock changes, refunds, fulfilments, API keys, billing — are written to your account’s audit trail with the user, the time and the IP address, on every plan.
- Active
GDPR-aligned controls
Built around GDPR principles: right-to-erasure and data-export workflows, and a Data Processing Agreement available to every merchant.
- Active
Incident response
Documented incident-response procedures with 72-hour breach notification, as committed in the DPA.
- Targeting Q4 2026
SOC 2 Type II
The audit is scheduled for Q4 2026 and controls are being implemented ahead of it. We are not certified today, and we will not claim otherwise until there is a report to send you.
Accountability
Nothing consequential happens without a person.
The routines that run inside your account work to limits you set, and the work they propose waits for you. Each item carries its reasoning and an Approve or Reject button, and the decision stays on the ledger afterwards. Approvals and limits are on every plan.
Sub-processors
Three companies, and what each one does.
BestWebby runs on a deliberately small set of infrastructure providers. Where a provider processes personal data on behalf of merchants, it acts as a sub-processor under our DPA.
- Hetzner Online GmbHGermany
- Cloud hosting — platform data is stored in EU data centers
- Cloudflare, Inc.Global edge
- DNS, CDN, bot protection, and DDoS mitigation in front of the platform
- Stripe, Inc.Global
- Platform subscription billing. Your customers pay into your own Stripe account, which you contract with directly
We notify merchants before engaging or replacing a sub-processor, as set out in the Data Processing Agreement. For the current list, or to ask about one of them, use our contact form.
Your data
Export it or erase it, whenever you want.
We act as a Data Processor for the data your customers generate, and as a Data Controller for our own account holders. In both roles the exit is open.
Merchants can request a full data export or an erasure at any time — from the dashboard Settings page or through our contact form — and we respond to every request within 72 hours. Nothing is held back to make leaving harder.
Responsible disclosure
If you find a vulnerability, report it to us privately before disclosing it publicly. We acknowledge reports within 24 hours and resolve valid ones within 30 days.
Report it through our contact formReport a vulnerability: email [email protected] — our contact details are also published at /.well-known/security.txt.
Please include reproduction steps and your estimate of the impact. A PGP key is available on request.
Seeing a store hosted on BestWebby doing something it shouldn’t — phishing, counterfeits, a scam? That’s a different queue: report abuse.
Send us the questionnaire.
Security reviews, DPA requirements, procurement forms — send them over and we will work through them with you rather than pointing you at a PDF.
