This is a draft version of this page. The content still needs to be reviewed by a lawyer before publication.
Separation between shops
Loyalo's database cannot be reached directly from the browser: row-level security is on for every table and public access is revoked. Only Loyalo's server functions read and write. Each request is tied to one shop there, based on the Shopify session, and only fetches that shop's data, so stores cannot reach each other's data.
Encrypted keys
Mollie API keys you connect to Loyalo are stored encrypted with AES-GCM. Loyalo does not store card or bank details of end customers, only payment references and mandate IDs returned by Mollie.
Roles
Access for staff, both at your store and at Loyalo.ai, part of Web Builders, is managed through roles. This lets you decide per team member what they may do: manage everything, only the daily work around subscriptions and customers, or only look.
Audit log
Administrative actions, such as changes to settings, roles or connected accounts, are recorded in an audit log. This makes it possible to see who made which change and when.
Backups
Data is backed up regularly as part of the European hosting environment, so data can be restored in case of technical issues.
Monitoring and health checks
Loyalo monitors the status of critical components, such as the Shopify connection, payment processing via Mollie and sending transactional email via Resend, so disruptions are noticed quickly.
Incident process
In the event of a security incident, Loyalo investigates the cause and impact, takes measures to limit further damage, and informs affected stores without undue delay, so they can meet their own obligations to customers and regulators.
Responsible vulnerability disclosure
Found a vulnerability in Loyalo? We appreciate a responsible report to info@loyalo.ai, with enough detail to reproduce the issue. Please do not disclose the vulnerability publicly until we've had a chance to address it.
More information
For security questions, or to arrange additional information for your own risk assessment, contact info@loyalo.ai.