Security
Your data is not our product.
We do not sell it, mine it, or stand between you and your customers’ money. What follows is the detail behind that sentence: where the data physically sits, who else touches it, what is encrypted, and what we have not certified yet.
Send us your vendor questionnaire · a person answers it, not a form letter
- Where platform data is stored
- EU
- Hetzner data centres, Germany
- On every connection
- TLS 1.2+
- TLS 1.3 preferred, HSTS one year, no HTTP fallback
- Named sub-processors
- 5
- Hosting, network, billing and model providers — listed below
- To complete a data request
- 30 days
- Export in Settings any time; erasure on request
Where the data lives
EU data centres, in Germany.
Platform data is stored in EU data centres on dedicated infrastructure operated by Hetzner Online GmbH. We state it plainly because where data lives is usually the first question a merchant asks, and the hardest one to get a straight answer to.
There is no on-premise or self-hosted edition. Every merchant runs on the same hosted platform — which is precisely why one set of controls can cover everyone.
Infrastructure is redundant and monitored continuously from the inside. You will not find an uptime figure quoted on this page: when we commit to one it will be in a contract, where it means something.
Infrastructure
- Hosted in EU data centers on dedicated infrastructure
- PostgreSQL with automated daily backups
- Redis-backed job queues for background processing
- Cloudflare for CDN, bot protection, and DDoS mitigation
- Private network between all internal services — no public service-to-service traffic
- Secrets managed via environment variables; never committed to version control
Controls
What is in place, and what is not.
Each control with its real status. Anything still on the roadmap says so on the same line as the thing it belongs to, so nothing has to be read twice.
- Active
Encryption in transit
Every connection is encrypted with TLS 1.2 or higher, and TLS 1.3 is used wherever the client supports it. HTTP Strict Transport Security is set with a one-year max-age, and there is no HTTP fallback.
- Active
Credential encryption
Sensitive credentials and secrets — API keys, integration tokens — are encrypted at the column level. Full-disk and backup encryption are on the hardening roadmap rather than in place today.
- Active
Access control
Internal access follows least-privilege principles, and platform-admin rights are an allowlist held in deployment configuration rather than a role anyone can grant from inside the app. Your own team’s actions — product and stock changes, refunds, fulfilments, API keys, billing — are written to your account’s audit trail with the user, the time and the IP address, on every plan.
- Active
GDPR-aligned controls
Built around GDPR principles: right-to-erasure and data-export workflows, and a Data Processing Agreement that every merchant accepts as part of signing up.
- In progress
Incident response
The DPA commits us to notify affected merchants of a personal data breach without undue delay. The written incident-response runbook, with who does what and by when, is still being completed, so this control is not marked active yet.
Accountability
Nothing consequential happens without a person.
The routines that run inside your account work to limits you set, and the work they propose waits for you. Each item carries its reasoning and an Approve or Reject button, and the decision stays on the ledger afterwards. Approvals and limits are on every plan.
Sub-processors
Who else processes the data, and why.
Where a provider processes personal data on behalf of merchants, it acts as a sub-processor under our DPA. Each one is listed with what it does, where it processes the data, and the safeguard we rely on when data leaves the EU.
- Hetzner Online GmbHGermany
- Hosting. Platform data, including databases, files and backups, is stored in its EU data centres.
- Transfer safeguard: Within the EU. No transfer.
- Cloudflare, Inc.United States, with a global edge network
- DNS, CDN, bot protection and DDoS mitigation. Traffic to the platform and to storefronts passes through it.
- Transfer safeguard: EU–U.S. Data Privacy Framework (certified recipient), and Standard Contractual Clauses.
- Stripe, Inc.United States
- Billing for the platform itself. Your customers pay into your own Stripe account, which you contract with directly.
- Transfer safeguard: EU–U.S. Data Privacy Framework (certified recipient), and Standard Contractual Clauses.
- Google LLC (Gemini API)United States and other countries where Google operates
- Language and image models behind suggested replies to customer messages and reviews, support and dispute assistance, listing screening, reading invoices and images, and image generation. It receives the text or image the feature needs.
- Transfer safeguard: EU–U.S. Data Privacy Framework (certified recipient). Processor terms for this use are being confirmed.
- Groq, Inc.United States
- Language models for the same features, and speech-to-text for storefront voice search. It receives the text a feature needs, or the voice clip a shopper records to search.
- Transfer safeguard: Standard Contractual Clauses are being put in place.
We email merchants at least 30 days before engaging or replacing a sub-processor, and a merchant may object, as set out in the Data Processing Agreement. To ask about one of them, use our contact form.
Your data
Export it or erase it, whenever you want.
We act as a Data Processor for the data your customers generate, and as a Data Controller for our own account holders. In both roles the exit is open.
Merchants can request a full data export or an erasure at any time — from the dashboard Settings page or through our contact form — and we complete every request within 30 days. Nothing is held back to make leaving harder.
Responsible disclosure
If you find a vulnerability, report it to us privately before disclosing it publicly. We acknowledge reports within 24 hours and resolve valid ones within 30 days.
Report it through our contact formReport a vulnerability: email [email protected] — our contact details are also published at /.well-known/security.txt.
Please include reproduction steps and your estimate of the impact. A PGP key is available on request.
Seeing a store hosted on BestWebby doing something it shouldn’t — phishing, counterfeits, a scam? That’s a different queue: report abuse.
Send us the questionnaire.
Security reviews, DPA requirements, procurement forms — send them over and we will work through them with you rather than pointing you at a PDF.
