Trust & Security
We're new. That's a fair reason to ask questions.
This page sets out how Aida handles your business data today. Where we can't give a specific answer here, we say so and tell you how to ask us.
[ 01 ]
Where your data is stored
Aida runs on Cloudflare: application hosting, server execution, the database, file storage and email routing. That covers account identifiers, your merchant records (sales, customers, rewards, invoices), files and technical records.
Card payments are handled by our payment partner. Outgoing email (such as receipts and invoice reminders) is sent through Resend, and company mailboxes use Google Workspace. Where you use AI features, the relevant content is sent to OpenAI and Aida requests that API responses are not stored. The full list is on the Subprocessors page.
Some providers may process personal data outside the European Economic Area. Where they do, Aida relies on a transfer mechanism such as an adequacy decision, the EU–U.S. Data Privacy Framework where valid for that provider, or Standard Contractual Clauses.
Sources: Subprocessors · Privacy Policy
[ 02 ]
Supabase for sign-in
Sign-in and sessions are handled by Supabase, which processes your name, company, email, authentication records and session data. Passwords are handled by the authentication provider; Aida verifies the sign-in token on the server against Supabase's published signing keys.
Supabase is used for sign-in only. Merchant data is hosted on the Cloudflare infrastructure above. We don't list the Supabase region here; ask us.
Sources: Subprocessors · Privacy Policy
[ 03 ]
How card payments work
Card payments are processed by our payment partner. Card details go directly to the payment partner and never touch Aida servers. A card sale, card refund or payout only changes in Aida when our payment partner confirms it to our servers.
Aida is not a bank, payment institution or e-money issuer, and it does not hold, receive or transmit your funds. Balances, payouts and card fees shown in Aida come from our payment partner.
Sources: Terms of Service · Subprocessors
[ 04 ]
Export and data ownership
You keep ownership of the data you submit. Aida may host, copy, transmit and display it only as needed to provide, secure and support the service. For personal data about your customers, your business is the controller and Aida acts as the processor under our Data Protection terms. Aida does not sell personal data.
You can export transactions, customers, invoices and accounting files (e-conomic, Dinero and Billy formats) as CSV at any time, and ask us for a full export.
Sources: Terms of Service · Data Protection
[ 05 ]
Access controls
Owners control who joins a merchant account and with which role: Owner, Admin, Manager, Finance, Analyst or Staff. Every role is checked on the server. For example, Staff can sell but not refund, and only an Owner or Finance can mark a bank-transfer invoice as paid.
Each merchant's sales, customers and rewards are separated and checked on every request. Our safeguards also include encrypted transport, server-side secret handling, input validation and monitoring of operational errors. People authorised to process customer data are bound by confidentiality.
Sources: Data Protection · Privacy Policy
[ 06 ]
Backups and recovery
Backups. The database uses Cloudflare D1 Time Travel, which is always on: every change is recorded, and the database can be restored to any minute within Cloudflare's retention window (at least the last 7 days). There are no separate scheduled backup jobs to forget.
Deleted data can take additional time to clear from this history. We use reasonable care to keep the service running, but we don't promise uninterrupted availability.
Sources: Data Protection · Terms of Service
[ 07 ]
If you leave Aida
You can stop using the service at any time and request account deletion. Export the records you need first. On termination or written request, Aida deletes or returns customer personal data, unless the law requires us to keep it. If Aida ever discontinues the service, our terms provide for reasonable notice and a chance to export your data where practical. We don't have a published escrow arrangement.
Sources: Data Protection · Terms of Service
[ 08 ]
Who is behind Aida
Aida is built by Gabriel Gerrits, sole founder, based in Odense, Denmark, who operates the service. Our terms are governed by Danish law. You can complain to the Danish Data Protection Agency (Datatilsynet) about how your personal data is handled.
Contact us or call +45 25 56 07 08.
Sources: Privacy Policy · Terms of Service
[ 09 ]
Have a security question?
Contact us with any security or data question, or to report a vulnerability. A person reads every message. If you suspect a security incident affecting your account, report it straight away. If Aida becomes aware of a personal-data breach affecting customer data, we notify the customer without undue delay.