Security

Your data, protected

Multi-tenant isolation, encrypted connections, automated backups, and compliance with GDPR and KVKK. Security is infrastructure, not an add-on.

Security built into every layer

Multi-Tenant Isolation

Each store runs in its own isolated environment. Separate databases, separate containers, separate networks. Your data never mixes with other stores.

Encrypted Connections

All traffic encrypted with TLS 1.3. Automatic SSL certificates for every domain. No unencrypted data in transit.

Automated Backups

Daily automated database backups with point-in-time recovery. Your data is never more than 24 hours from a restore point.

GDPR & KVKK Compliant

Built for European and Turkish data protection regulations. Data processing agreements, cookie consent, and right to deletion supported.

Authentication & Access

JWT-based authentication, session management, and role-based access control. Admin accounts are protected with secure password policies.

Infrastructure

Hosted on enterprise-grade infrastructure. DDoS protection, firewall rules, and network-level security. Automatic updates and patching.

Compliance & data handling

Data Processing

We process data only as necessary to provide the service. No selling data to third parties. No cross-store tracking.

Right to Deletion

Request complete data deletion at any time. We remove all your data from our systems within 30 days of account closure.

Data Export

Export all your data (products, customers, orders, content) at any time in standard formats. No vendor lock-in.

Data Residency

Data stored in European data centers. GDPR-compliant data handling and transfer policies.

Security FAQ

Your data is stored in European data centers with enterprise-grade infrastructure. Each store has its own isolated database.
No. Each store is completely isolated — separate database, separate container, separate network. There is no data sharing between stores.
You can export all your data before cancellation. After account closure, all data is permanently deleted from our systems within 30 days.
Admin accounts use JWT-based authentication with secure session management. Two-factor authentication is on our roadmap.
We never store credit card numbers. All payment processing is handled by Stripe or Iyzico — both PCI DSS Level 1 certified.

Questions about security?

We take security seriously. Contact us if you need more details about our security practices.