# How does Zubs keep your store’s data secure?

> Source: https://zubs.app/security
> Title: Security at Zubs: Hosting, Data and Payments — Zubs
> Language: en

## Short answer

Zubs runs on servers in the EU and never sees your customers’ card details: Shopify charges every subscription order and keeps the payment methods. Zubs only acts on requests Shopify has signed for your store, and as a GDPR processor it works on your customers’ data on your behalf.

## Who runs Zubs, and where is it hosted?

Zubs is built and run by Zubs GmbH, a company registered in Germany. The Zubs app runs on servers in the EU, in the Netherlands.

- The app, the API and the scheduled jobs (billing runs, the Inventory Planner, reminders) run on Railway, in its EU region in the Netherlands. How Railway secures its platform is set out in [Railway’s trust center](https://trust.railway.com/)
- Error monitoring, the emails Zubs sends to your customers and product analytics also run in EU data centers.
- Our support team answers in English and German.
- Company details: [legal notices](https://zubs.app/legal-notices)

## Does Zubs see or store card details?

No. Shopify processes every payment and keeps the payment methods; Zubs never receives card numbers or security codes.

- Zubs asks Shopify to charge a subscription order, and Shopify charges the customer’s saved payment method through your store’s payment gateway.
- Zubs keeps only Shopify’s reference to a payment method, never the card itself.
- When a card needs updating, Shopify emails the customer a secure link where they enter the new details with Shopify. [Help center: billing address and payment method](https://help.zubs.app/docs/subscription-management/subscription-addresses/)

## What data does Zubs store, and why?

Zubs keeps what it needs to run your subscriptions: your account and settings, and the subscription data it processes for you. Shopify stays the system of record for your orders, customers and subscription contracts.

- About your store: shop name, the owner’s email address, country, your settings, and the name and email of the staff member signed in to the app.
- About your customers, on your behalf: names, contact details, addresses, and subscription and order details, so Zubs can bill, ship, send emails and show you analytics.
- A search index of customer names, email addresses and product titles, so you can find a subscription in the Zubs admin.
- How long each kind of data is kept is set out in the [privacy policy](https://zubs.app/privacy-policy)

## How does Zubs access my Shopify store?

Through Shopify’s standard app installation: you approve the permissions Shopify shows you, and Shopify issues Zubs an access token for your store only.

- Zubs keeps the token on its servers and uses it there to call Shopify’s API for your store.
- When you uninstall Zubs, Shopify revokes the access, and Zubs deletes the stored access tokens and sign-in sessions for your store as soon as possible.

## How does Zubs check who is asking for data?

Every request from the Shopify admin, the customer portal, checkout or your storefront carries a token or signature from Shopify, and Zubs verifies it before it answers.

- Zubs takes the store from Shopify’s signed token, not from what the request claims, so one store can’t ask for another store’s data.
- In the customer portal, a request is only accepted with a token Shopify issued for a signed-in customer.
- Requests through your storefront’s app proxy are checked against Shopify’s signature.

## How do events from Shopify reach Zubs?

Shopify’s notifications about your store (a new subscription, a billing result, an uninstall) are verified and processed through a secured queue that only Zubs can read.

- Zubs reads that queue with its own credentials, so nothing on the open internet can post an event in Shopify’s name.
- Events Shopify sends over HTTPS instead are accepted only with a valid Shopify HMAC signature.

## Is data encrypted on its way?

Yes. Zubs is served over HTTPS, and the Zubs admin tells browsers to connect only over HTTPS (HSTS).

- Zubs talks to Shopify, error monitoring and the email service over their HTTPS APIs.

## How does Zubs notice when something goes wrong?

Errors in the app, the API and the extensions are reported to an error monitoring service in the EU, so the team sees a failure when it happens.

- When the API reports a GraphQL error, it first removes values named like passwords, tokens, API keys or card numbers from the request details.

## Which services process data for Zubs?

Zubs uses a small set of service providers to run the app. Where a provider offers a region, Zubs uses its EU region.

- Shopify: your store, its customers, orders and payments.
- Railway: hosting of the app, the API and the scheduled jobs (EU, Netherlands). [Railway’s trust center](https://trust.railway.com/)
- Further providers for the delivery of Shopify’s notifications, error monitoring, the emails Zubs sends to your customers, product analytics, address search and the data behind the analytics dashboard.
- Klaviyo receives subscription events only if you connect your own Klaviyo account.
- The full list of sub-processors comes with the data processing agreement, on request.

## How does Zubs handle GDPR?

For your customers’ data you are the controller and Zubs is the processor: Zubs processes that data only to provide the app, on your instructions.

- A data processing agreement (DPA) with technical and organizational measures is available on request, based on the Zubs template named in the terms. [Terms and conditions](https://zubs.app/terms-and-conditions)
- Your data stays yours: you can export it for up to one month after the contract ends.
- What Zubs processes, why and for how long is in the [privacy policy](https://zubs.app/privacy-policy)

## How do I report a security vulnerability?

Email us with what you found, the steps to reproduce it and the store or URL it affects. Please test only against your own store, don’t access or change other merchants’ or customers’ data, and give us time to fix the issue before you disclose it. We’ll confirm we got your report and keep you posted.

Security reports: [info@zubs.app](mailto:info@zubs.app)

## Bottom line

Zubs leaves payments with Shopify, runs in the EU and checks Shopify’s signature on every request. As your GDPR processor it stores only what it needs to run your subscriptions; your IT or legal team can ask for the DPA, and anyone who finds a vulnerability can reach us by email.

## Frequently asked questions

### Is Zubs PCI compliant?

Zubs never handles card data, so card data never touches Zubs’ systems. Shopify processes the payments and keeps the payment methods; Zubs only asks Shopify to charge a subscription order.

### Where is Zubs hosted?

The Zubs app runs on Railway servers in the EU, in the Netherlands. Error monitoring, customer emails and product analytics also run in EU data centers.

### Can I get a data processing agreement (DPA)?

Yes. Zubs provides a DPA with technical and organizational measures and the full list of sub-processors on request, based on its own template. Send the request to the contact address in the legal notices.

### What happens to my data when I uninstall Zubs?

Shopify revokes Zubs’ access, and Zubs deletes your store’s access tokens and sign-in sessions as soon as possible. How long the remaining data is kept is set out in the privacy policy.

### Is there an uptime commitment?

Yes. The terms commit to 99.0% monthly availability of the software, with service credits if Zubs falls short.

## Related

- [Zubs facts](https://zubs.app/facts)
- [Privacy policy](https://zubs.app/privacy-policy)
- [Terms and conditions](https://zubs.app/terms-and-conditions)
- [Legal notices](https://zubs.app/legal-notices)
