Skip to main content

01 / Security & trust

Dependable, compliant, and yours to leave.

Your data stays in the UK. Cards never touch our servers. Every change is logged and tamper-evident — and you can export everything, any time.

02 / Trust pillars

UK data residency

Primary application data hosted on a dedicated server in London, UK, with in-region backups. Some named sub-processors process data outside the UK under appropriate safeguards.

UK GDPR

We act as processor for your customer data and controller for your own account data, with a full Article 28 DPA and sub-processor register available on request.

Your customers' card details never touch us

Payments are handled directly by Stripe and GoCardless's own secure systems — we never see or store a full card number. (The technical standard is PCI SAQ-A, the lowest-risk compliance tier.)

Nothing edited quietly, after the fact

Every change is permanently recorded, not just the current state — and every signed agreement carries a tamper-proof history that can prove it was never altered.

Roles & least privilege

Every operator's data is walled off from every other operator's — enforced at the database level, not just in application code — plus strict staff access limits and two-factor authentication for our own team.

No lock-in — export your data

Everything you can see in the product is available over the public API, and a full structured export is available at any time.

03 / Status & uptime

StoreBay is built so nothing is silently lost, and we monitor service health continuously. We don't yet publish a contractual uptime SLA — that qualitative honesty matters more to us than a number we can't stand behind yet.

See live status →

04 / Sub-processors

DigitalOcean (London, UK) · Stripe · GoCardless · Resend · Bird · Xero / QuickBooks. Request our DPA →

05 / Legal

Read the underlying documents

UK-resident · auditable · no lock-in

Ready to talk security with us directly?