Data security
Last updated: 2026-08-06
At iqseller, operated by Enlasys S. de R.L. de C.V., we handle your business and sales-channel data (Amazon, MercadoLibre, 3PL) with the utmost care. This page explains our security practices.
data we process
- Catalog, inventory, pricing, orders and sales metrics from your connected channels.
- Channel API access via OAuth authorization — we never store your passwords.
- Your iqseller account data (email, organization, users).
what iqseller runs on
We don't operate our own servers. The application and the database run on two providers audited by independent third parties:
Serves the application and this site.
- SOC 2 Type 2 and ISO 27001:2013
- PCI DSS v4.0 (AOC as service provider and as merchant)
- GDPR and Data Privacy Framework
- Automatic DDoS mitigation
Database, authentication and storage, on AWS.
- SOC 2 Type 2 and ISO 27001
- GDPR, with a data processing agreement available
- AES-256 encryption at rest
- Managed database backups
We also rely on a small set of providers for specific functions —product analytics, transactional email and assistive features— which receive only the data needed for that function. The full list is in our privacy notice.
Certifications checked against each provider's official source (vercel.com/security and supabase.com/security) on August 6, 2026.
What these certifications mean — and what they don't. They belong to our providers and cover their own infrastructure: their data centers, their processes, their controls. iqseller does not currently hold its own SOC 2 or ISO 27001 certification. Running on certified providers is not the same as being certified. We'd rather tell you plainly than have you find out later. The day we obtain our own certification, we'll publish it here with its scope and date.
where your data lives
The dashboard's database is hosted in the AWS us-east-1 region (United States). As stated in our privacy notice, this means some data is processed outside México, with the corresponding protection safeguards.
encryption
All data travels encrypted in transit (TLS/HTTPS) and is stored encrypted at rest with AES-256, both in the database and in file storage.
The tokens we use to reach your channels' APIs are protected by that encryption at rest and are used only from our servers, to make calls to Amazon or MercadoLibre on your behalf. No screen in the dashboard displays them and no response from our API returns them.
per-account isolation (multi-tenant)
Each organization can only access its own data. Isolation is enforced in two layers: the server resolves which organization you belong to from your session, not from a value the browser can choose, and filters by it when querying; on top of that, the database has row-level security (RLS) enabled on all its tables.
Every code change goes through an automated test suite —including org-isolation checks— and through review before reaching production.
web application security
- No passwords. You sign in with your Google account or a single-use code sent to your email, typed in the same tab. We don't send sign-in links —software opens them before the person does, which burns the code— and we don't store passwords, so there are no passwords to leak.
- Full security headers. The dashboard applies Content-Security-Policy, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy across all its routes, limiting what the browser can load or execute and blocking the app from being embedded in third-party sites.
- Verifiable by you. You don't have to take our word for it: these headers are public and you can audit them with an external scanner at securityheaders.com.
least privilege
We request from each channel only the permissions (scopes/roles) the platform needs to function. We don't request buyer PII unless strictly necessary for a feature you enable. You can revoke access at any time.
retention and deletion
We keep your data while your account is active. You can request export or deletion anytime at privacidad@iqseller.app. On account closure we delete or anonymize your data within a reasonable period, unless legally required to retain it.
internal access control
Team access to production systems is restricted by operational need and authentication. We keep relevant activity logs.
incident management
We have a process to detect and respond to security incidents. In case of a breach affecting you, we will notify you as required by applicable law.
marketplace compliance
We operate in line with the acceptable-use and data-protection policies of the channels we integrate, including the Amazon Selling Partner API.
Amazon and all related logos are trademarks of Amazon.com, Inc. or its affiliates. MercadoLibre and all related logos are trademarks of MercadoLibre, Inc. Vercel and Supabase are trademarks of their respective owners; their logos are shown solely to identify the infrastructure we run on. iqseller is an independent solution and is not endorsed by, sponsored by, or affiliated with any of them.
contact
Security questions? Email privacidad@iqseller.app.
Enlasys S. de R.L. de C.V. · J del Monte 39, Piso 2, Int 2B, Huixquilucan, Estado de México, 52764, México.