Legal

Data Security

This page describes the security controls that are actually in the current Pelro product. It does not claim certifications or guarantees we have not completed.

Last updated 15 August 2026

What is in place today

Access to dashboards and onboarding requires a signed-in session. Passwords are handled by Supabase Auth, not stored in application code.

Workspace data is scoped with row-level security so a signed-in user can only read and change records for workspaces they belong to.

Account emails use confirmation and password-reset links rather than exposing passwords. Production traffic is served over HTTPS.

The live commerce path is a validated CSV import. Integration cards for Shopify, ads, payments and couriers are shown as upcoming connectors and do not collect OAuth secrets in this MVP.

How you can reduce risk

Use a unique password, keep your inbox secure so verification links are not forwarded, and only invite teammates who should see your operating data.

Import only the commerce fields needed for decisions. Do not upload unrelated customer identity files or payment-card data.

Incident contact

If you believe there is a security issue in your workspace, sign out if needed and contact support. Include the Error ID if one is shown. We will investigate in good faith.

What this page does not claim

Pelro does not currently claim third-party security certification, a public bug-bounty programme, or that imported data is encrypted in a customer-managed key system. Those may be added later; they are not part of this description.

Questions about this page? Contact support (dropperai75@gmail.com)