We attach great importance to security and data protection. We only collect the data necessary for a smooth ordering process and also encrypt it. All of our services use HTTPS transport encryption.
The login data is stored in a separate application that only contains your email address, your password, two-factor authentication and, if applicable, information from the identity provider (when logging in via Google, Facebook, Discord, Instagram, Microsoft, Twitter or Paypal).
User data such as address, past orders or payment details are also stored separately and securely with AES-265 bit encryption. The shop frontend application does not have direct access to the database, but accesses it via a REST API.
It is important to note that data about orders older than 3 months will be automatically deleted in the User Data application. The only exceptions to this are legal requirements that require storage in our accounting application for at least 6 years.
In the unlikely event of a security gap in the shop front-end application, which can be extremely minimized but never completely ruled out due to extensive software testing before publication, no customer data can be queried or directly assigned to a customer.
Our entire software architecture is based on a so-called microservice framework, which sets us apart significantly from other shops.
For our content delivery network and DDoS protection, we use Cloudflare, whose edge nodes are positioned exclusively in Europe. Our applications are operated exclusively on servers in Europe, which are located in an ISO 27001 certified data center.
We attach great importance to an extremely high security standard for our servers. The systems are managed exclusively by our team and have state-of-the-art firewalls that only allow HTTPS connections. The hard drives are also encrypted. Administration takes place exclusively via a VPN connection, and access to the servers is only possible via unprivileged accounts with SSH key authentication.
The shop frontend application and the login application are the only components accessible over HTTPS via the Internet. All other applications are either completely isolated from the Internet or only accessible via a VPN connection.