Skip to main content

Security & compliance

How your catalogue is protected

Written plainly, including what we are still confirming.

Sign-in
Handled by a specialist identity provider. GetShopSync stores no passwords at all — there is nothing in our database for an attacker to steal. Every request carries a cryptographically verified session token, checked against the provider’s public keys on every call.
Separation between customers
Every product, brand, batch and file belongs to a catalogue, and every catalogue belongs to an account. Access is checked on the object itself, not only on the menu — a user cannot reach another account’s data by changing a number in a URL.
Permissions
Five levels, assigned per catalogue. Access is granted by explicit assignment, never by default.
Your files
Images and datasheets are copied into object storage under your account rather than hotlinked from suppliers. Uploads are validated by inspecting the file contents, not by trusting the file name. Datasheet links are cryptographically signed.
Fetching supplier sites
Capture only reaches public web addresses. Requests to internal or private network addresses are blocked, including through redirects.
Change history
Every product edit saves the complete previous state with the person and the time. Deletions are reversible — records are archived rather than destroyed.

POPIA

Protection of Personal Information Act

Smart Station (Pty) Ltd is a South African company and GetShopSync is subject to POPIA.

The personal information we hold about your staff is limited to what is needed to operate accounts: name, email address, contact details, and a record of the actions each user takes. Your product data is commercial information, not personal information.

Sub-processors. Our AI extraction provider, our identity provider, two object-storage providers and our database provider. Each processes data only on our instruction, and we will name them all in writing on request.

Being straight with you about cross-border transfer

Some of these providers process data outside South Africa. We are completing a full data-residency map and will publish it, along with the transfer basis for each processor, before making any compliance claim. We would rather tell you this is in progress than claim a certification we do not hold.

If your procurement process needs a definitive answer today, ask us on the call and we will give you the current position in writing.

Information officer: [SUPPLY name and email]

Security questions before you commit?

Send them through and we will answer in writing, including the ones where the answer is “not yet”.