Security

How we look after your data

A plain summary of the safeguards in Aida today. More detail, including where data is stored, is on our Trust page.

Card payments

Card payments are processed by our payment partner. Card details go directly to the payment partner and never touch Aida servers, and Aida does not store full card numbers. A card sale, refund or payout only changes in Aida when our payment partner confirms it to our servers. Opening a pay page or a browser redirect never marks a sale as paid.

Signing in

Sign-in and sessions are handled by Supabase. Passwords are handled by the sign-in provider, and Aida checks every sign-in token on the server against Supabase's published signing keys.

Who can see what

Owners control who joins a merchant account and with which role: Owner, Admin, Manager, Finance, Analyst or Staff. Every role is checked on the server. For example, Staff can sell but not refund. Each merchant's sales, customers and rewards are kept separate and checked on every request.

Safeguards

  • Encrypted connections (HTTPS) to Aida.
  • Secrets are handled on the server, and saved integration credentials are encrypted and never returned to the browser.
  • Input validation and limits on what can be sent to Aida.
  • Monitoring of operational errors.
  • People authorised to process customer data are bound by confidentiality.

Backups

The database uses Cloudflare D1 Time Travel, which is always on: every change is recorded, and the database can be restored to any minute within Cloudflare's retention window (at least the last 7 days). We use reasonable care to keep the service running, but we don't promise uninterrupted availability.

If something goes wrong

If Aida becomes aware of a personal-data breach affecting customer data, we notify the affected merchant without undue delay.

Report a security issue

Contact us with any security question, or to report a vulnerability or a suspected incident affecting your account. A person reads every message. Please give us enough detail to reproduce the issue, and don't access or change other people's data while testing.

See also: Trust · Data Protection · Subprocessors · Privacy