Trust & Security
Security
Last updated: 23 July 2026
Read-only Shopify access
We request the minimum Shopify scopes and never write to your store, change settings, or touch customer data. You can revoke access from your Shopify admin at any time.
Encrypted in transit & at rest
All traffic runs over TLS 1.2+. Data is stored encrypted at rest by our EU infrastructure providers.
Built & hosted in the EU
Your data is stored and processed inside the EU, in line with GDPR. No transfers to third countries without a lawful basis.
We never store card details
Payments are handled entirely by Stripe (PCI DSS Level 1). Card numbers never reach our servers.
1. How we access your Shopify store
Profflow connects to Shopify through the official API using read-only scopes. We pull the data needed to calculate your real profit — orders, revenue, refunds, and Shopify fees. We never modify your store, its settings, your products, or your customers, and we do not process payments on your behalf. You can disconnect Profflow at any time from your Shopify admin, which immediately revokes our access.
2. Data encryption
All data transmitted between your browser, Profflow, and our providers is encrypted in transit using TLS 1.2 or higher. Data stored in our database is encrypted at rest by our infrastructure providers.
3. Where your data lives
Profflow is built and hosted in the European Union. Your store data and account data are stored and processed within the EU in line with the GDPR. We do not sell your data or share it with advertisers.
4. Payments
All payments are processed by Stripe, a PCI DSS Level 1 certified provider. Card details are entered directly into Stripe's secure checkout and never reach or get stored on Profflow's servers. EU VAT is calculated automatically at checkout.
5. Account security
Access to your dashboard is protected by your email and password, managed through our authentication provider. We recommend using a strong, unique password. Passwords are stored only as salted hashes — we can never see them.
6. Access controls
Only authorised Profflow personnel can access production systems, and only when necessary to operate or support the service. Administrative access is limited and logged.
7. Responsible disclosure
If you believe you've found a security vulnerability, please email security@profflow.co with the details. We take every report seriously, will acknowledge it promptly, and ask that you give us a reasonable window to fix the issue before any public disclosure.
8. Data deletion
You can request deletion of your account and associated data at any time. Once your account is closed, connected data is removed in line with our Privacy Policy, typically within 30 days.
9. Contact
Questions about security or data handling: security@profflow.co. Profflow Analytics OÜ, Tallinn, Estonia · VAT EE103006985.