How Altimeter keeps your data safe
Altimeter shows you your profit. To do that it holds your sales data and a little about your customers. Here is how we look after it.
We only read, never write
Every connection to your tools is read-only. Altimeter cannot change an order, a product, a customer, an ad or an email. Shopify and Meta connect through their own sign-in with read-only permissions, and a Shopify grant that includes any write permission is refused.
We keep as little as possible
From your customers we keep only name and email, with their orders. No addresses, phone numbers or payment details. Emails are masked in customer lists. We never sell data, never use it for marketing, and never combine it with other merchants' data.
Your data has its own database
Each brand's data lives in its own separate database. It has no public address; only Altimeter's service can reach it, and only after checking that you are signed in and belong to that brand. The database itself refuses requests for any other brand, and our tests check this.
Encrypted everywhere
- Stored data is encrypted by Cloudflare (AES-256).
- Everything travels over HTTPS.
- Your tools' access keys get an extra layer: each is encrypted on its own (RSA-OAEP + AES-256-GCM), and the key that unlocks them exists only inside the running service. Nobody, including us, can view a saved key.
Sign-in and roles
- Nobody sees anything without signing in. Today sign-in is handled by Cloudflare Access, with a one-time code sent to an invited email address; no passwords. We are moving to Clerk, with multi-factor authentication available.
- Your team has roles: owners and admins can change settings and connections, viewers can only look.
- Changes to settings and connections record who made them and when.
Built on Cloudflare
Altimeter runs on Cloudflare Workers, D1 and Durable Objects. Cloudflare holds independent certifications for its infrastructure, including SOC 2 Type II and ISO/IEC 27001. Those cover Cloudflare's systems; Altimeter itself has not been separately audited yet.
Backups and recovery
Cloudflare keeps a rolling 30-day history of every database, so data can be restored to any point in that window. Because we only read from your tools, your data can also be synced again from the source.
Careful engineering
Our test environment never stores your customers' real names or emails; they are replaced with stand-ins as data is written. Our code is in a private repository. Every change goes through a pull request with automated checks, and dependencies are kept up to date automatically.
When you leave
Uninstall the app and your data is deleted within 48 hours of Shopify's deletion request (sent 48 hours after uninstall). Cancel another way and it is deleted within 30 days. Backups age out within 30 more days.
If something goes wrong
We have a written incident response plan. If a breach affects your data, we will tell you without undue delay, and within 72 hours of becoming aware.
Questions or a security report
media@vxdigital.co. Full details: Privacy Policy, Data Processing Agreement.