How we keep your store and your customers' data safe.
You trust AjVik with your orders, your customers' addresses and the keys to your carrier and payment accounts. Here is what we do with that trust, in plain words.
Your data is walled off from other sellers
Every record in AjVik belongs to one business, and the database itself refuses to return another business's rows. On top of that, the application checks which business you are working in on every request. Automated tests try to read one seller's data from another seller's account on every code change.
Encrypted on the move and at rest
Every page, API call and storefront is served over HTTPS, including custom domains, which get their certificate automatically. Stored data sits on encrypted disks and storage. The keys and tokens you connect, such as carrier, marketplace and ad account credentials, are encrypted separately before they are saved.
We never see card numbers
Customers pay through AjVik Payments, powered by Stripe, or through PayPal. Card and bank details are entered with Stripe or PayPal, which are PCI DSS compliant, not with AjVik, and the money is paid out to your bank account, not ours.
Roles and permissions
Invite your team and give each person a role, such as owner, manager or warehouse staff, so they see only what their job needs. Access is denied unless a role allows it. You can remove a team member's access at any time.
Audit log
Important changes, such as prices, refunds, settings and team access, are recorded with who made them and when. Owners can review the audit log in the console.
Safer sign-in
Turn on 2-step verification with an authenticator app, with backup codes in case you lose your phone. See the devices signed in to your account and sign out any of them. Unusual sign-ins, such as a new device, trigger an extra check and an alert.
The parts you don't see
Backups
Databases are backed up automatically. Backups are encrypted and kept in the same data region as the live data.
Data residency
AjVik is built so that each business's data stays inside one regional boundary. Enterprise customers can ask for a dedicated data region.
Staff access
AjVik staff don't browse seller data. When support needs to look at your account, the access requires a reason and is recorded.
Safe uploads
Files you and your customers upload are checked by their content, not only their file name, and are served from a separate address from the app.
Rate limits
Sign-in, one-time passwords and other sensitive actions are rate-limited to slow down password guessing and message abuse.
Secrets handling
Passwords are stored as strong one-way hashes. Application secrets are kept out of the code.
Data requests, handled inside the product
When a shopper asks what you hold about them, or asks you to delete it, you can deal with the request from the console instead of digging through spreadsheets. AjVik supports requests under US state privacy laws such as the CCPA and, for customers in the UK and EU, GDPR.
Read our privacy policy for what AjVik collects and why.
Found a security problem?
Please tell us privately at info@ajvik.com with "Security" in the subject. Include the steps to reproduce it and what you think the impact is.
Please don't access other people's data, disrupt the service or share the issue publicly before we have fixed it. We will confirm receipt, keep you updated and credit you if you'd like.
Security questions
Can't find what you're looking for? Our team replies within one working day.
Is AjVik SOC 2 or ISO 27001 certified?
Not today. We are working towards SOC 2, and ISO 27001 where sellers in Europe need it, and we design our controls with those standards in mind. We will say so here when an audit is complete, and not before.
Who owns my store data?
You do. Your products, orders and customer list belong to your business. You can export your data from the console, and we do not sell seller or shopper data.
How do I handle a customer's request to see or delete their data?
AjVik supports privacy requests under US state privacy laws such as the California Consumer Privacy Act (CCPA, as amended by the CPRA), the EU and UK General Data Protection Regulation (GDPR) and India's DPDP Act, including access, correction, export and deletion. Customer consent for marketing is recorded per channel, and only opted-in customers receive broadcasts.
Can someone on my team see everything?
Only if you give them a role that allows it. Owners decide each member's role, and changes to team access are recorded in the audit log.
What happens to my data if I stop using AjVik?
When a trial or plan ends, your store goes read-only rather than being deleted, and you can reactivate it within 30 days. You can export your data before you leave, or ask us to delete your account.
Build your store on a platform that takes data seriously.
Seven days to try everything with real customers. Pick a plan when you are ready.
- 7-day trial on every plan
- No card needed to start
- $0 setup, cancel any time
- Payments settle to your own bank