Security

How Waktaa protects shop data

A short summary of how the product is hosted and protected. For privacy roles and channel rules, see Trust and the Privacy Policy.

Controls

What runs in production

Data location

Product data sits in Google Cloud SQL for PostgreSQL in Virginia, United States. The marketing site is served from Cloudflare.

Encryption in transit

Public product traffic uses HTTPS. Incoming webhooks are verified with provider signatures.

Encryption at rest

Cloud SQL encrypts disks with Google-managed encryption. Channel OAuth access and refresh tokens are sealed with AES-256-GCM in the database.

Access and isolation

Operators sign in with Google. Each organization only sees its own data; membership is checked before inbox and account actions.

Data loss prevention

Protected customer data (name, email, phone) stays tenant-scoped. Channel OAuth tokens are AES-256-GCM sealed. Cloud SQL disks are encrypted. We do not sell customer data. Retention and deletion follow the Privacy Policy and DPA. Production access is limited to operators who need it for support and incident response.

Access logging for customer data

When staff open a conversation or person record that includes customer name, email, or phone, the product writes a durable audit entry: who accessed it, which organization and thread, and which field types were present—without copying the field values into the log. Platform admins can review these entries.

Backups

Cloud SQL automated backups run daily with seven retained backups.

Report a vulnerability

Tell us before it is public

Email hello@waktaa.com with the subject “Security vulnerability”. Include steps to reproduce and impact. We aim to acknowledge within one business day.

hello@waktaa.com

Also see Trust and the Privacy Policy.

Ask a questionStart free