Piaflo
Home Features Pricing Help Blog
EN
English Français
Install app
Piaflo
HomeFeaturesPricingHelpBlog Install app
EN FR
Legal

Security & data protection

Last updated: October 2, 2026

How Piaflo protects the data of merchants and their customers. Questions or vulnerability reports: [email protected].

Hosting

  • Application, database, media and backups are hosted by Hetzner Online GmbH in Germany (EU).
  • The service runs in isolated containers behind a reverse proxy; only HTTPS (443) and SSH with key authentication are exposed.
  • Traffic passes through Cloudflare for DNS, TLS and network protection.

Encryption

  • In transit: TLS everywhere (storefront, admin, webhooks, APIs). Webhooks from Shopify and Zernio are verified with HMAC-SHA256 signatures.
  • At rest: personal fields (names, phone numbers, email addresses, consent evidence), message contents and payloads, flow contexts and raw webhook events are encrypted in the database with AES-256-GCM. Phone numbers and emails use deterministic encryption so they can be matched without being stored in clear. Media received from customers are encrypted on disk.
  • Backups: daily database snapshots are compressed and encrypted with AES-256-GCM before being written to a separate backup volume, with an optional off-site copy. Unencrypted backups are never written.
  • Encryption keys are stored only in the production environment configuration, never in the source code or the repository.

Data loss prevention

  • Daily encrypted backups, kept 14 days, with a documented and tested restore procedure.
  • Consistent snapshots (VACUUM INTO) taken without downtime.
  • Database in write-ahead-log mode; database migrations applied automatically and reviewed before release.
  • Retention limits and automatic purges keep only the data needed (see the Privacy Policy).
  • Outgoing messages use idempotency keys so a failure never sends a message twice.

Separation of environments

Development and tests use separate databases with synthetic data and fake WhatsApp transport. Production data is never copied to development machines.

Access control

  • Only the founder-engineer has production access (SSH key with passphrase, two-factor authentication on Shopify, GitHub, Meta and hosting accounts).
  • Staff passwords: minimum 14 characters, unique per service, stored in a password manager, with two-factor authentication wherever available.
  • Inside the app, every view of contacts and conversations by merchant staff is recorded in an access log (who, what, when), kept 12 months. Production administrative access is recorded in an access register.
  • Merchant staff authenticate through Shopify (session tokens); the app never handles merchant passwords.

Application security

  • Signed and verified webhooks, server-side plan checks, no secrets in the client.
  • Dependencies kept up to date; type checking, linting and automated tests run before every release.
  • Customer messages are treated as untrusted input (escaped in the interface, never executed).

Incident response

We follow a written incident response policy: detection, containment, assessment, notification of affected merchants without undue delay and within 48 hours of confirming a personal data breach (so merchants can meet their 72-hour GDPR obligation), remediation and post-mortem.

Compliance

  • Shopify mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) are implemented and tested.
  • WhatsApp marketing consent is stored in Shopify's native consent field, with proof of consent kept by Piaflo; STOP is honored immediately.
  • A Data Processing Agreement is part of our Terms — see the DPA.

Security incident response policy

Applies to any event that may compromise the confidentiality, integrity or availability of data processed by Piaflo (merchant data, customer personal data, WhatsApp account access). Owner: the Piaflo security lead ([email protected]).

1. Detection and reporting

  • Sources: error and anomaly alerts (failed webhook signatures, unusual access patterns, sending queue anomalies), Shopify/Meta/Zernio/Hetzner notices, merchant or researcher reports to [email protected].
  • Anyone who suspects an incident reports it immediately; every report is logged with time, source and description.

2. Triage (within 4 hours)

Classify severity:

  • Critical: confirmed or likely access to personal data by an unauthorized party, leaked credentials or encryption keys, compromise of WhatsApp sending.
  • High: vulnerability exploitable to access personal data, prolonged outage of message sending.
  • Low: other security events without data exposure.

3. Containment

As applicable: rotate exposed secrets (Shopify API secret, Zernio key, webhook secrets, encryption key), revoke tokens, turn on the global sending kill switch, block offending IPs, take affected services offline, preserve logs and evidence.

4. Assessment

Determine the data, stores and customers affected, the period, the root cause and the risk to individuals. Use the access log, server logs and backups.

5. Notification

  • Merchants (data controllers) affected by a personal data breach are notified without undue delay and within 48 hours of confirmation, with: nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken and proposed, and a contact point — so that they can notify their authority within 72 hours (GDPR art. 33) and data subjects if required (art. 34).
  • Shopify is notified as required by the Shopify Partner Program Agreement and API Terms; Meta/Zernio when WhatsApp assets are involved.
  • Authorities are notified directly where Piaflo acts as controller (merchant staff data).

6. Recovery

Fix the root cause, restore from encrypted backups if needed (procedure in scripts/restore-backup.ts), verify integrity, monitor closely for 30 days.

7. Post-incident review

Within 10 business days: written timeline, root cause, impact, what worked, corrective actions with owners and dates. The policy is updated accordingly.

8. Review

This policy is reviewed at least once a year and after every critical incident.

Piaflo

WhatsApp flows for Shopify stores. Recover checkouts, confirm cash on delivery orders and keep customers posted, with Meta fees at cost.

WhatsApp is a trademark of WhatsApp LLC. Piaflo is an independent Shopify app and is not affiliated with or endorsed by Meta or WhatsApp.

Product

  • Features
  • Pricing
  • FAQ
  • Install on Shopify

Resources

  • Connect your WhatsApp number
  • Blog
  • Contact support

Legal

  • Privacy policy
  • Terms of service
  • Data processing agreement
  • Security
© 2026 Piaflo. All rights reserved.