Skip to content

Security

Built as a multi-tenant system from the first line.

PixlBridge holds access tokens for your ad accounts and hashed identifiers for your customers. These are the controls that protect them, described the way we describe them internally.

Details

What we do, specifically

Data we hold

  • Account data: name, email (verified), bcrypt password hash, workspace membership and role.
  • Provider credentials: encrypted OAuth tokens for Meta, Amazon and Shopify, plus the account, pixel, profile, advertiser and store identifiers you selected.
  • Click data: link code, timestamp, fbclid-derived identifier, first-party browser id, device and browser type, normalised IP, user agent.
  • Conversion data: Amazon Attribution order aggregates per tag; Shopify order values, currency, line item ids and SHA-256 hashed customer identifiers.
  • Billing: Stripe customer and subscription ids. Card details never touch PixlBridge.

Where it goes

Hashed identifiers and commerce data are sent to Meta's Conversions API for the dataset you selected. Attribution tags are created in your Amazon Ads account. Nothing is sold, shared with advertisers other than you, or used to build cross-customer profiles. The full list of sub-processors is in the data processing addendum.

GDPR and Shopify compliance webhooks

The Shopify app implements customers/data_request, customers/redactand shop/redact. Customer erasure removes the hashed identifiers for that customer; shop redaction removes the store's data. Account deletion by a workspace owner cascades through every table.

Reviewed, not assumed

The codebase carries a written threat model and a security review with reproduced attack cases for each finding; the regression tests stay in the suite. Findings and accepted residual risks are tracked with owners. We run dependency audits and keep the runtime on current Node and Postgres releases.

Operational safeguards

  • Database not reachable from the internet; only the reverse proxy is exposed.
  • Nightly encrypted database backups with off-site copies; the encryption key is stored separately from backups.
  • Every background job run is recorded per workspace with status and error, which powers the health views you see in the app.
  • Swagger/API documentation is disabled in production unless explicitly enabled and password protected.

Reporting a vulnerability

Email security@pixlbridge.com. We acknowledge within two business days, keep you informed, and credit researchers who wish to be credited. Please do not access other customers' data while testing; use your own free workspace.

Questions about compliance or a security questionnaire?

Write to us and we will answer with specifics, not marketing.