Security
Built as a multi-tenant system from the first line.
PixlBridge holds access tokens for your ad accounts and hashed identifiers for your customers. These are the controls that protect them, described the way we describe them internally.
Encryption at rest and in transit
Meta, Amazon and Shopify tokens are encrypted with AES-256-GCM before they touch the database, using a key kept outside it. All traffic is HTTPS; certificates are issued and renewed automatically.
Hashed personal data
Email, phone, name, address and customer ids from Shopify orders are normalised and SHA-256 hashed at ingest. Raw values are never stored or logged. Click records keep a normalised IP and a hashed IP; private and unknown IPs are dropped.
Tenant isolation
Every data table carries a workspace id. A tenant-scoped database client injects it into every read and write; routes cannot reach it any other way. Cross-tenant tests run in CI: seed workspace A, call as B, expect nothing.
Signed webhooks, single-use state
Shopify and Stripe webhooks are verified with timing-safe HMAC checks and refused when a secret is missing; deliveries are idempotent. OAuth uses 32-byte random state bound to workspace, user and provider, valid for ten minutes, consumed once.
Least privilege
Roles owner, admin, member and viewer; role and membership are re-read from the database on every request, never trusted from the token. Platform-operator access is separate, time-limited and written to an audit log.
Hardened public paths
Redirect destinations are restricted to Amazon hosts, never arbitrary URLs. Rate limits protect sign-in, sign-up, password reset, invites and the pixel beacon. Error responses never include stack traces or database details.
Details
What we do, specifically
Data we hold
- Account data: name, email (verified), bcrypt password hash, workspace membership and role.
- Provider credentials: encrypted OAuth tokens for Meta, Amazon and Shopify, plus the account, pixel, profile, advertiser and store identifiers you selected.
- Click data: link code, timestamp, fbclid-derived identifier, first-party browser id, device and browser type, normalised IP, user agent.
- Conversion data: Amazon Attribution order aggregates per tag; Shopify order values, currency, line item ids and SHA-256 hashed customer identifiers.
- Billing: Stripe customer and subscription ids. Card details never touch PixlBridge.
Where it goes
Hashed identifiers and commerce data are sent to Meta's Conversions API for the dataset you selected. Attribution tags are created in your Amazon Ads account. Nothing is sold, shared with advertisers other than you, or used to build cross-customer profiles. The full list of sub-processors is in the data processing addendum.
GDPR and Shopify compliance webhooks
The Shopify app implements customers/data_request, customers/redactand shop/redact. Customer erasure removes the hashed identifiers for that customer; shop redaction removes the store's data. Account deletion by a workspace owner cascades through every table.
Reviewed, not assumed
The codebase carries a written threat model and a security review with reproduced attack cases for each finding; the regression tests stay in the suite. Findings and accepted residual risks are tracked with owners. We run dependency audits and keep the runtime on current Node and Postgres releases.
Operational safeguards
- Database not reachable from the internet; only the reverse proxy is exposed.
- Nightly encrypted database backups with off-site copies; the encryption key is stored separately from backups.
- Every background job run is recorded per workspace with status and error, which powers the health views you see in the app.
- Swagger/API documentation is disabled in production unless explicitly enabled and password protected.
Reporting a vulnerability
Email security@pixlbridge.com. We acknowledge within two business days, keep you informed, and credit researchers who wish to be credited. Please do not access other customers' data while testing; use your own free workspace.
Questions about compliance or a security questionnaire?
Write to us and we will answer with specifics, not marketing.