01 / Security & trust
Dependable, compliant, and yours to leave.
Your data stays in the UK. Cards never touch our servers. Every change is logged and tamper-evident — and you can export everything, any time.
02 / Trust pillars
UK data residency
Primary application data hosted on a dedicated server in London, UK, with in-region backups. Some named sub-processors process data outside the UK under appropriate safeguards.
UK GDPR
We act as processor for your customer data and controller for your own account data, with a full Article 28 DPA and sub-processor register available on request.
Your customers' card details never touch us
Payments are handled directly by Stripe and GoCardless's own secure systems — we never see or store a full card number. (The technical standard is PCI SAQ-A, the lowest-risk compliance tier.)
Nothing edited quietly, after the fact
Every change is permanently recorded, not just the current state — and every signed agreement carries a tamper-proof history that can prove it was never altered.
Roles & least privilege
Every operator's data is walled off from every other operator's — enforced at the database level, not just in application code — plus strict staff access limits and two-factor authentication for our own team.
No lock-in — export your data
Everything you can see in the product is available over the public API, and a full structured export is available at any time.
03 / Status & uptime
StoreBay is built so nothing is silently lost, and we monitor service health continuously. We don't yet publish a contractual uptime SLA — that qualitative honesty matters more to us than a number we can't stand behind yet.
See live status →04 / Sub-processors
05 / Legal