Skip to main content

Security

Your data is not our product.

We do not sell it, mine it, or stand between you and your customers’ money. What follows is the detail behind that sentence: where the data physically sits, who else touches it, what is encrypted, and what we have not certified yet.

Send us your vendor questionnaire · a person answers it, not a form letter

Where platform data is stored
EU

Hetzner data centres, Germany

On every connection
TLS 1.3

HSTS, one-year max-age, no HTTP fallback

Named sub-processors
3

Hetzner, Cloudflare, Stripe — listed below

Response to a data request
72h

Export or erasure, on request

Where the data lives

EU data centres, in Germany.

Platform data is stored in EU data centres on dedicated infrastructure operated by Hetzner Online GmbH. That is worth stating plainly, because for a European merchant it is usually the first question and the hardest one to get a straight answer to.

There is no on-premise or self-hosted edition. Every merchant runs on the same hosted platform — which is precisely why one set of controls can cover everyone.

Infrastructure is redundant and monitored continuously from the inside. You will not find an uptime figure quoted on this page: when we commit to one it will be in a contract, where it means something.

Infrastructure

  • Hosted in EU data centers on dedicated infrastructure
  • PostgreSQL with automated daily backups
  • Redis-backed job queues for background processing
  • Cloudflare for CDN, bot protection, and DDoS mitigation
  • Private network between all internal services — no public service-to-service traffic
  • Secrets managed via environment variables; never committed to version control

Controls

What is in place, and what is not.

Six controls, each with its real status. Anything still on the roadmap says so on the same line as the thing it belongs to, so nothing has to be read twice.

  • Encryption in transit

    TLS 1.3 is enforced on every connection. HTTP Strict Transport Security is set with a one-year max-age, and there is no HTTP fallback.

    Active
  • Credential encryption

    Sensitive credentials and secrets — API keys, integration tokens — are encrypted at the column level. Full-disk and backup encryption are on the hardening roadmap rather than in place today.

    Active
  • Access control

    Internal access follows least-privilege principles, and platform-admin rights are an allowlist held in deployment configuration rather than a role anyone can grant from inside the app. Your own team’s actions — product and stock changes, refunds, fulfilments, API keys, billing — are written to your account’s audit trail with the user, the time and the IP address, on every plan.

    Active
  • GDPR-aligned controls

    Built around GDPR principles: right-to-erasure and data-export workflows, and a Data Processing Agreement available to every merchant.

    Active
  • Incident response

    Documented incident-response procedures with 72-hour breach notification, as committed in the DPA.

    Active
  • SOC 2 Type II

    The audit is scheduled for Q4 2026 and controls are being implemented ahead of it. We are not certified today, and we will not claim otherwise until there is a report to send you.

    Targeting Q4 2026

Accountability

Nothing consequential happens without a person.

The routines that run inside your account work to limits you set, and the work they propose waits for you. Each item carries its reasoning and an Approve or Reject button, and the decision stays on the ledger afterwards. Approvals and limits are on every plan.

The Approvals and limits screen, on its Ledger tab: twelve items awaiting approval and none done this week, filters for all, awaiting you, done, rejected and undone, and proposal cards — each a drafted reply to a product review, with a “Why this” disclosure and Approve, Reject and Details buttons.
The approvals ledger. What was proposed, why it was proposed, who decided, and when — kept as a record rather than as a notification you can miss.

Sub-processors

Three companies, and what each one does.

BestWebby runs on a deliberately small set of infrastructure providers. Where a provider processes personal data on behalf of merchants, it acts as a sub-processor under our DPA.

Hetzner Online GmbHGermany
Cloud hosting — platform data is stored in EU data centers
Cloudflare, Inc.Global edge
DNS, CDN, bot protection, and DDoS mitigation in front of the platform
Stripe, Inc.Global
Platform subscription billing. Your customers pay into your own Stripe account, which you contract with directly

We notify merchants before engaging or replacing a sub-processor, as set out in the Data Processing Agreement. For the current list, or to ask about one of them, use our contact form.

Your data

Export it or erase it, whenever you want.

We act as a Data Processor for the data your customers generate, and as a Data Controller for our own account holders. In both roles the exit is open.

Merchants can request a full data export or an erasure at any time — from the dashboard Settings page or through our contact form — and we respond to every request within 72 hours. Nothing is held back to make leaving harder.

Responsible disclosure

If you find a vulnerability, report it to us privately before disclosing it publicly. We acknowledge reports within 24 hours and resolve valid ones within 30 days.

Report it through our contact form

Report a vulnerability: email [email protected] — our contact details are also published at /.well-known/security.txt.

Please include reproduction steps and your estimate of the impact. A PGP key is available on request.

Seeing a store hosted on BestWebby doing something it shouldn’t — phishing, counterfeits, a scam? That’s a different queue: report abuse.

Send us the questionnaire.

Security reviews, DPA requirements, procurement forms — send them over and we will work through them with you rather than pointing you at a PDF.