Security & Data Protection

Last updated: 8 July 2026

Our role

Vibel is a data processor. We read your store data (orders, customers, products, fulfillments) only to give you analytics and operational insights on your own store. We never sell personal data and never use it, or any data sent to our AI provider, to train third-party models.

Data minimization & least privilege

We request the minimum Shopify access needed: read-only order, product, inventory and fulfillment scopes, and only the customer fields required for order and shipping analytics. Optional connectors (Klaviyo, Meta, Google Ads, GA4, Search Console, TikTok, Pinterest, Stripe, AfterShip, Gorgias, Zendesk, Monday, QuickBooks Online) use their own read-only or least-privilege scopes and are only queried for brands that connect them.

Encryption

All data is encrypted in transit (TLS) and at rest (Supabase's managed encryption-at-rest). Provider access tokens are held in Supabase Vault, a dedicated encrypted secrets store, and are referenced elsewhere only by an opaque ID, never held in plain tables or exposed to the browser.

Access control & tenant isolation

Every table is protected by Postgres row-level security scoped to the owning brand, so one merchant's data is not reachable from another's session. Application data is read server-side only; the browser never talks to the database directly. Staff access to personal data is restricted and logged.

Webhook & API security

Inbound Shopify webhooks (order/fulfillment events, billing updates, and the mandatory privacy webhooks below) are verified against their HMAC signature before we act on them; unverified or malformed requests are rejected.

Retention & deletion

Personal data is retained only while needed to provide the service. We honor Shopify's mandatory privacy webhooks: a customer erasure request deletes that customer's stored data, and 48 hours after uninstall we delete the shop's order, product, and customer data. You can also request deletion at any time by contacting us.

Test and production data

Development and testing use synthetic demo data only. Real merchant and customer data is never used for testing and is isolated per tenant in production.

Subprocessors

Supabase (database, authentication, encrypted secrets vault, storage), Vercel (application hosting), Anthropic (AI processing via the Claude API, no training on customer data), and Resend (transactional email). Each maintains its own security program and provides encryption in transit and at rest.

Incident response

On discovery of a suspected personal-data breach we: (1) contain immediately by rotating affected credentials, revoking tokens and isolating the affected system; (2) assess the scope and the merchants and customers affected within 24 hours; (3) notify affected merchants without undue delay and, where GDPR applies, within 72 hours, describing the nature of the incident, the data involved and the remediation; (4) remediate the root cause and document the incident; and (5) review and harden to prevent recurrence.

Responsible disclosure

If you believe you've found a security vulnerability, please report it to us before disclosing it publicly. Email a description and steps to reproduce to the address below; we will acknowledge your report and work with you on a fix timeline before any public disclosure.

Contact

Security questions or reports: post@stephancolen.nl.

Terms · Privacy