This policy says how we protect Stallkeep and the information shops keep in it. It only describes what is true today. Anything we haven't finished yet is marked Planned.
Scope
The Stallkeep platform: this website, the help centre, the Stallkeep admin our team uses, every shop's back office (where shop owners and staff work), and every shop's online storefront, including shops on their own domain.
Who is responsible
This policy belongs to Design Studio Lab Ltd. Stallkeep is a trading name of Design Studio Lab Ltd, registered in England and Wales, company number 11222280. Registered office: 2 Damara Way, Ashford TN25 7FD. The company director owns it, makes sure it is followed, and leads the response to any security incident.
Data classification
We put every kind of information into one of four levels and handle it by that level.
Public
- What: this website, the help centre guides, and what a shop publishes on its storefront.
- Handling: anyone may read it. Only our team can change our website, and only a shop's staff can change its storefront.
- Encryption: sent over HTTPS, as described under Encryption below.
- Access: anyone can read it.
Internal
- What: business data, such as a shop's products, costs, stock, suppliers, sales figures and settings, and Stallkeep's own business records.
- Handling: each shop's data is kept in its own separate database. Changes to stock and issued invoices are only ever added to, never rewritten.
- Encryption: HTTPS in transit, as described below.
- Access: that shop's staff, only as far as their role allows (for example, cost prices are hidden from staff without that permission), and the Stallkeep team when needed to run or support the service.
Confidential
- What: personal data of shop owners, staff and shoppers, such as names, email addresses, delivery addresses and order history. Once marketplace connections go live, buyer details from marketplaces such as TikTok Shop will be treated the same way Planned.
- Handling: used only to run the service. For a shop's customers we act only on the shop's instructions, as its processor. Kept and deleted as our retention periods say. Our support desk hides anything that looks like a card number, password or key before a message is saved.
- Encryption: HTTPS in transit, as described below. Passwords are stored only as a one-way hash.
- Access: the shop's own staff, as their role allows, and the minimum Stallkeep team needed to support the shop.
Restricted
- What: secrets: payment, courier and Google keys and access tokens, two-step sign-in secrets, database passwords.
- Handling: entered only in Stallkeep's own settings screens. By design, once set up they aren't shown again in full, and we don't write them to our logs or activity records.
- Encryption: encrypted in the database with AES-256.
- Access: a shop's keys only through its Settings, by staff whose role allows it. Stallkeep's own keys can only be changed by the company's owners.
Access control and two-step sign-in
- Shop staff see only their own shop, and only what their role allows. When an owner removes someone, they are signed out straight away.
- In the Stallkeep admin, only the company's owners can change platform settings and keys.
- Every Stallkeep admin account must use two-step sign-in with an authenticator app. A used code can't be used again.
- Shop owners and staff can switch on two-step sign-in for their own accounts, and we ask them to. Requiring it for shop owners is Planned.
- Staff and admin passwords must be at least 12 characters, and every password is stored only as a one-way hash (bcrypt), so nobody can read it, including us.
- Sign-in attempts are rate-limited. A per-account lock after repeated failed attempts, with an email to the account holder, is Planned.
Encryption in transit and at rest
- In transit: information is encrypted between your browser and Cloudflare, which fronts our service (HTTPS). Full end-to-end encryption all the way to our servers is being completed Planned. Our connections to Stripe and PayPal use HTTPS.
- At rest: passwords are hashed. Keys, access tokens and two-step secrets are encrypted in the database (AES-256).
- This website sends three browser security headers: nosniff (X-Content-Type-Options), a referrer policy, and framing protection (X-Frame-Options). Adding them to the back office, the admin and shops' storefronts is Planned. HTTP Strict Transport Security (HSTS) and a Content Security Policy are Planned.
How secrets are stored
- Every stored key, token and two-step secret is kept in an encrypted database column. By design, once set up it isn't sent back to the browser in full (a two-step secret is shown only while it is being set up).
- Keys are entered only in Stallkeep's own settings screens: Stallkeep's in the admin, and a shop's in its back office Settings.
- We will never ask you for a password, key or sign-in code by chat, phone or email. If one is pasted into a support message by mistake, our support desk hides it before the message is saved.
Payments
Card payments are handled by Stripe and PayPal, which are PCI DSS Level 1 certified. Shoppers enter their card details on Stripe's or PayPal's own pages, so Stallkeep never sees or stores card numbers. Payment confirmations from Stripe are checked with a signature, and the amount and currency must match the basket.
Backups
Nightly encrypted backups to private Cloudflare R2 storage are being switched on Planned. This section will describe them once the first backup has run.
Suppliers and sub-processors
The companies that handle personal data for us, what each does and what data it receives, are listed in our Trust centre's sub-processor list. Each gets only what it needs for its job. Hosting is with IONOS, and traffic passes through Cloudflare.
Logging and monitoring
- Sign-ins, failed sign-ins and failed two-step codes are recorded, in the Stallkeep admin's audit log and in each shop's activity log.
- The audit log and shops' activity logs record who changed what and can only be added to, never edited.
- By design, we don't write passwords, keys or card numbers to our logs.
- The admin's Health page shows the state of the service.
- Uptime monitoring and error alerts are Planned.
Incident response
The company director leads the response to any security incident. We contain the problem, find out what happened and which shops and data were affected, and fix the cause. We tell affected shops without undue delay. Where UK GDPR requires it, we report a personal data breach to the Information Commissioner's Office within 72 hours of becoming aware of it. The full steps are in our Trust centre.
Reporting a vulnerability
If you think you've found a security weakness in Stallkeep, please tell us before anyone else. Email [email protected] (also listed in our security.txt). We read every report. Please don't access, change or delete other people's data, don't run tests that could slow down or disrupt shops, and give us a reasonable time to fix the problem before you share it.
Staff and devices
We aim to keep full-disk encryption, a screen lock and automatic updates on the devices used to run Stallkeep. Confirming two-step sign-in is on for every outside account used to run it, such as hosting, code, domain, payment and email accounts, is Planned. Getting certified under the UK government's Cyber Essentials scheme is Planned.
Review
Last reviewed 11 October 2026. We review this policy at least once a year, and whenever how we run Stallkeep changes in a way that affects it.