Data Security Practices
MerchantFlow data security practices including 2FA authentication, AES-256 encryption, session management, mobile device tokens, tenant isolation, and OAuth token security.
Data Security
Effective Date: December 27, 2025
MerchantFlow data security encompasses the technical and organizational measures that protect your business data, integration credentials, and account information. At MerchantFlow Pty Ltd, we implement industry-standard encryption, authentication, session management, and access controls to ensure your data remains private and secure.
Authentication Security
Two-Factor Authentication (2FA)
MerchantFlow uses Better Auth for authentication with support for two-factor authentication (2FA).
2FA features:
- TOTP-based (Time-based One-Time Password) authentication, 6 digits on a 30-second period
- Compatible with authenticator apps such as Google Authenticator, Authy, and 1Password
- Mandatory, not optional, for every account that signs in with an email address and password. Workspace owners are required to enable it during onboarding, and invited team members before the dashboard opens
- Social sign-in accounts (Google, Facebook) with no MerchantFlow password are exempt, because they are secured by the identity provider, as are sessions inside the Shopify-embedded app
- Ten single-use backup codes are issued at setup and can be regenerated from Settings > General, which invalidates the previous set
Password Security
MerchantFlow enforces strict password validation requirements at signup, on invitation acceptance, and on password reset:
- Minimum 8 characters in length
- Must contain at least one uppercase letter, one lowercase letter, one digit, and one special character
- All passwords are securely hashed and salted before storage
- Plaintext passwords are never stored or logged
The in-dashboard Change Password form enforces the same requirements, in the browser before submission and again on the server.
For password management, see Password Reset.
Session Security
MerchantFlow implements comprehensive session management to protect your account:
| Setting | Value | Description |
|---|---|---|
| Session expiry | 30 days | A browser session expires 30 days after it was last refreshed |
| Update age | 1 day | An active session is refreshed at most once per day |
| Cookie cache | 5 minutes | Cookie validation is cached for 5 minutes for performance |
The values above apply to browser sessions. Paired mobile devices use a different credential with a different lifetime - see Mobile App Security below.
Additional session protections:
- Secure, HTTP-only session cookies, marked Secure in production
- A password reset revokes every active session across all browsers and devices. Changing your password from within the dashboard does not
- Paired mobile devices are listed and individually revocable under Settings > Developer > Mobile. They are a separate credential and are not affected by browser session revocation
Mobile App Security
The MerchantFlow mobile app authenticates with a device access token, not a browser session, so the values in the previous section do not apply to it:
| Setting | Value | Description |
|---|---|---|
| Device token lifetime | 90 days | A paired device's credential expires 90 days after it is issued |
| Renewal | None | Using the app does not extend the expiry. When it lapses you sign in or pair again |
| Pairing code validity | 5 minutes | Pairing codes are short-lived and can be used once |
Additional mobile protections:
- The device token is stored on our servers as an irreversible hash only, with a short non-secret prefix retained so you can recognize the device in your device list
- Pairing codes are likewise stored as hashes only, never in plaintext
- On the device, the token is held in the operating system's secure credential store (iOS Keychain, or Android Keystore-backed encrypted storage) and is bound to that device, so it is not carried into device backups
- No business data is written to the device. Figures are held in memory only while the app is running
- The app has no separate PIN or biometric lock, so your device lock screen is the local protection for a paired session
- Every paired device can be revoked individually at Settings > Developer > Mobile, and a device's access also ends when you sign out in the app or when the user or workspace is deleted
Tenant Isolation
MerchantFlow keeps each account's data strictly isolated through tenant isolation:
- Each tenant's data is logically separated and cannot be accessed by other tenants
- Your data is only accessible to your account and authorized team members
- Cross-tenant data access is architecturally prevented
- Team members within a tenant share access based on their assigned roles
OAuth and Integration Security
Encrypted Tokens
All OAuth tokens for connected integrations are encrypted at rest. Integration credentials are stored securely and never exposed in logs or API responses.
No Password Storage for Integrations
MerchantFlow uses OAuth 2.0 only for third-party integrations. We never ask for or store passwords for services such as Google, Shopify, WooCommerce, or Meta.
Read-Only Access
MerchantFlow requests read-only access to your integrations wherever possible:
- Google Ads - read-only access to campaign and performance data
- Google Analytics 4 - read-only access to traffic and conversion data
- Google Search Console - read-only access to search performance data
- Google Merchant Center - read-only access to product feed data
- Shopify - read-only access only. The app requests
read_orders,read_all_orders,read_analytics,read_inventory,read_locations,read_products,read_reports, andread_customers, and holds no write scope of any kind - WooCommerce - read-only access to orders and product data
- Meta Ads - read-only access to campaign performance data
We never modify your data, create campaigns, or make changes to your connected platforms.
Token Revocation
You can revoke integration access at any time:
- Go to Settings > Integrations
- Click "Disconnect" on the integration
- OAuth tokens are immediately deleted
- You can also revoke access from the third-party platform directly
Payment Security
All payment processing is handled by Stripe, which is PCI DSS compliant:
- MerchantFlow never sees or stores your credit card numbers
- Payment data is transmitted directly to Stripe over encrypted connections
- Stripe handles all payment card validation and fraud detection
Encryption Standards
Encryption in Transit
- All data transmitted over HTTPS/TLS (TLS 1.2 or higher enforced)
- Insecure connections are rejected
Encryption at Rest
- AES-256-GCM application-level encryption for OAuth and integration credentials
- AES-256-GCM application-level encryption for customer personal data on order records: customer name, email address, phone number, shipping address, and tracking number. Searchable fields are additionally stored as peppered one-way hashes so lookups never require decrypting the whole table
- Backups are encrypted
Data Retention and Purge
MerchantFlow implements automatic data retention policies:
- Data types such as audit logs, sync logs, analytics snapshots, notifications, and integration logs are subject to configurable retention periods, applied by a purge job that runs daily
- Once those retention periods lapse, that log data is permanently purged
- Audit log retention cannot be disabled and cannot be set below 365 days
- Retention periods balance operational needs with data minimization principles
- Mobile device records, including expired and revoked devices, are kept for the life of the account so that your device list and its history remain available to you, and are deleted when the user or workspace is deleted
For full retention details, see GDPR Compliance.
Account Deletion
Account deletion is available to the workspace owner only, from Settings > Delete Account. When you delete your account:
- All personal data is removed, immediately and irreversibly - there is no grace period
- Integration tokens are revoked and deleted
- Synced data is permanently purged, and every paired mobile device loses access
- Any active Stripe subscription is cancelled
- Backups are removed within 90 days
Security Best Practices for Users
- Enable 2FA on your MerchantFlow account
- Use a strong, unique password that meets the requirements above
- Do not share your account credentials
- Review your paired mobile devices regularly at Settings > Developer > Mobile and revoke any you do not recognize. To end browser sessions everywhere, run a password reset
- Keep your email secure as it is used for account recovery
- Disconnect unused integrations to minimize your data footprint
- Report suspicious activity immediately to [email protected]
Reporting Security Issues
If you discover a security vulnerability or have concerns about data security:
- Email: [email protected]
- Subject: Security Issue
- Responsible disclosure is appreciated
- We acknowledge receipt within 24 hours
Frequently Asked Questions
Does MerchantFlow store my credit card information?
No. All payment processing is handled by Stripe (PCI DSS compliant). MerchantFlow never sees, processes, or stores payment card numbers.
Can other MerchantFlow users see my data?
No. MerchantFlow uses tenant isolation to architecturally prevent cross-account data access. Your data is only visible to your workspace team members based on their assigned roles.
What happens to my data if MerchantFlow experiences a security breach?
In the event of a breach, MerchantFlow follows its incident response plan: immediate investigation, notification to affected users within 72 hours (GDPR requirement), remediation, and post-incident review.
Is my data backed up?
Yes. Data is backed up with encryption and removed from backups within 90 days of account deletion. Our infrastructure and backups are hosted with Hetzner in Finland.
Related Resources
Last updated: August 29, 2026
Last updated on