Security

Effective from: 24 June 2026

Last updated: 19 July 2026

This page describes the basic security measures of the ProfitEcom service.

It is intended for customers, partners, users and platforms that need to understand how ProfitEcom protects data, integrations and access.

The operator of the ProfitEcom service is:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771

Security contact: security@profitecom.com

Privacy contact: privacy@profitecom.com

General contact: hello@profitecom.com

1. Security approach

ProfitEcom processes business, marketing, economic and analytical data of its customers. The security of this data is a key part of operating the service.

We design security measures according to the nature of the processed data, the related risks, the infrastructure used and the practical needs of a B2B analytics platform.

Our goal is to protect in particular:

  • customer data,
  • data integrations,
  • authorization tokens,
  • user accounts,
  • analytical outputs,
  • backend systems,
  • the data platform,
  • access to the production environment.

2. Service architecture

ProfitEcom uses several technology layers:

  • Webflow for the marketing website,
  • WeWeb as the application frontend,
  • Auth0 for login and identity management,
  • Xano as the backend, API and database layer,
  • n8n as the integration and workflow layer,
  • Microsoft Fabric as the data and analytics platform,
  • Power BI for reporting and dashboards,
  • other external services according to specific integrations and customer implementations.

WeWeb serves as the frontend and does not have its own active customer data database.

Long-term authorization tokens are stored in the backend layer, not in WeWeb, Power BI or Fabric.

3. Regions and infrastructure

ProfitEcom data is primarily processed within the European Union or the European Economic Area.

We use in particular:

  • a dedicated Xano instance in Belgium,
  • Microsoft Fabric in the West Europe region,
  • Auth0 in the EU region,
  • self-hosted n8n on a Hetzner server in Nuremberg.

Some providers may process data outside the EU/EEA as part of their services. Details are provided in the Privacy Policy.

4. Login and identity

Login to the ProfitEcom application is provided by Auth0.

Users may log in using:

  • e-mail and password,
  • Google login,
  • Microsoft Enterprise login.

Google and Microsoft login are used only for user authentication. We do not use them to access e-mails, files, documents or other content in Google Workspace or Microsoft 365.

Users are assigned to a specific customer account or tenant. Access permissions are managed according to the user’s role and the customer’s settings.

5. Internal access

Internal access to production data is limited to persons who need it for the operation, development, support, administration or security of the service.

Access to key services is protected by multi-factor authentication.

Internal access to production data is limited in particular to:

  • development and service administration,
  • resolving technical issues,
  • customer support,
  • security and operational tasks,
  • infrastructure administration.

Access to production data is not provided to persons who do not need it for their work.

6. Separation of customer data

ProfitEcom is designed as a multi-tenant service.

Data of individual customers is separated at the tenant and permission level.

In reports and Power BI outputs, we use access controls, including row-level security (RLS), so that a user can see only the data of their own customer account or tenant.

When designing data models and reports, we take care to prevent unauthorized access to data of another customer.

7. Protection of authorization tokens

ProfitEcom uses OAuth and other authorization mechanisms to connect external platforms, such as Google Ads, Google Analytics or Meta.

ProfitEcom does not receive or store customer passwords for external platforms.

Long-term authorization tokens are stored in encrypted form in the backend infrastructure.

Long-term tokens:

  • are not displayed to users in the application,
  • are not stored in WeWeb,
  • are not stored in Fabric,
  • are not stored in Power BI,
  • are not used for purposes other than authorized data retrieval,
  • are removed or revoked when the integration is disconnected, according to the capabilities of the relevant platform.

Only short-term access tokens necessary to retrieve data from an authorized platform may be passed to the n8n integration layer.

8. Google Ads, Google Analytics and Meta integrations

We use Google Ads, Google Analytics and Meta integrations only to read data.

For these integrations, ProfitEcom:

  • does not create campaigns,
  • does not edit campaigns,
  • does not change budgets,
  • does not edit ads,
  • does not manage audiences,
  • does not delete advertising objects,
  • does not modify Google Analytics account or property settings,
  • does not create or change data streams, events, conversions or audiences in Google Analytics,
  • does not perform any write operations in Google Ads, Google Analytics or Meta accounts.

Retrieved data is used for reporting, analytics, web analytics, conversion evaluation, profitability calculations and connecting marketing, website and business data of the customer.

Authorization credentials for integrations are removed and, where possible, revoked when the integration is disconnected.

9. Encryption and data transmission

Data in transit is protected using encrypted HTTPS/TLS connections.

Encrypted transmission is used in particular when:

  • accessing the website,
  • accessing the application,
  • communicating between the frontend and backend,
  • calling APIs,
  • communicating with external platforms,
  • transferring data between integration and data layers.

Long-term authorization tokens are stored in encrypted form.

10. n8n integration layer

The n8n integration layer is used for workflow processing, retrieving data from external systems and transferring data to the data platform.

n8n is operated as a self-hosted service on a Hetzner server in Nuremberg.

Access to the server and n8n is limited to authorized persons.

For integration workflows where access tokens or other sensitive data may occur, we use appropriate measures to reduce the risk of such data being stored in workflow execution history.

Execution data is retained only for a limited period. For workflows involving sensitive tokens, data storage may be restricted or redacted according to technical capabilities.

Refresh tokens are not passed to n8n. n8n uses only short-term access tokens required for specific API calls.

11. Data platform and reporting

Data for reporting is stored and processed in Microsoft Fabric.

Reports and dashboards are made available through Power BI and the ProfitEcom application.

Access to reports is restricted according to the user, role and tenant.

In Fabric, we store marketing, web analytics, business and analytical data required for reporting. Long-term authorization tokens for external platforms are not stored in Fabric.

12. Processing of customer data

The standard ProfitEcom data model does not require direct identifiers of end customers of an e-commerce store, such as names, e-mail addresses, phone numbers or postal addresses.

If it is necessary to track repeat purchases or customer behavior in an aggregated form, a pseudonymized customer identifier is used.

For custom reports, the scope of processed data may be broader. Such processing is always based on an implementation analysis or a data scope specification.

Without an express agreement, we do not intend to process special categories of personal data or other sensitive data.

13. Logging and monitoring

ProfitEcom uses technical logs and operational records required for:

  • service operation,
  • error resolution,
  • security,
  • audit of technical issues,
  • integration diagnostics,
  • protection against unauthorized access.

Logs and execution data are retained only for the necessary technical period.

For integration workflows involving sensitive data, we aim to minimize the storage of sensitive values, such as access tokens.

14. Backups and recovery

The infrastructure and data service providers used by ProfitEcom may create backups or technical copies according to their standards.

ProfitEcom’s goal is that technical copies are not retained longer than necessary for recovery, security and service operation.

Backups and technical copies may exist for a limited period, with a target maximum of 90 days, unless a longer period follows from the provider’s technical settings or a legal obligation.

15. Development and test environments

ProfitEcom gradually uses separate or partially separate environments for development, testing and production, especially in Xano, Microsoft Fabric and WeWeb.

The goal is to minimize the use of production data in development and testing.

If the use of production data is necessary to resolve a specific issue, access is limited to authorized persons and only for the necessary period.

n8n is operated in a single environment, with access restricted to authorized persons.

16. Vulnerabilities and security reports

If you discover a security issue, vulnerability or suspected unauthorized access, please contact us at:

security@profitecom.com

Please include in your report:

  • a description of the issue,
  • the affected URL or service,
  • steps to reproduce, if available,
  • the potential impact,
  • a contact e-mail for communication.

We ask that any security testing is carried out in a way that does not damage the service, disrupt availability, access data of other customers or violate applicable law.

17. Security incidents

ProfitEcom has an internal procedure for handling security incidents.

When a suspected incident occurs, we proceed in particular as follows:

  • identify and verify the incident,
  • limit further impact,
  • secure relevant information and logs,
  • assess the scope and risk,
  • implement corrective measures,
  • inform affected customers where necessary,
  • cooperate with customers in meeting their legal obligations,
  • document the incident internally.

If an incident presents a risk to the rights and freedoms of natural persons, we proceed in accordance with applicable legal requirements.

18. What the customer is responsible for

Security of the service is a shared responsibility.

The customer is responsible in particular for:

  • managing its users,
  • assigning and removing roles,
  • protecting login credentials,
  • using secure devices,
  • controlling who has access to the application,
  • correct configuration of integrations,
  • authorization of persons who connect integrations,
  • the data it sends to ProfitEcom,
  • compliance with the data contract and implementation specification.

If a customer’s user leaves the company or should no longer have access, the customer should remove their access without delay.

19. External services and responsibility of third parties

ProfitEcom uses third-party services, such as Auth0, Microsoft, Xano, Hetzner, Webflow, Cookiebot, Mandrill, Stripe, Google, Meta and other providers according to the specific implementation or deployed tools.

The security of the service also depends on the availability and security measures of these providers.

ProfitEcom is not responsible for independent third-party systems outside its control, such as the customer’s accounts with Google, Google Analytics, Meta, Microsoft, an e-commerce platform, ERP or CRM.

20. Certifications

ProfitEcom currently does not claim its own security certification such as ISO 27001, SOC 2 or a similar certification.

In operating the service, we use reputable cloud and technology providers that have their own security programs, certifications and operational standards.

This page provides a public overview of ProfitEcom’s security measures. Detailed security information may be provided to customers to a reasonable extent depending on the contractual relationship and the nature of the request.

21. Changes to security measures

We may change and improve security measures over time.

Changes may relate in particular to:

  • development of the service,
  • infrastructure changes,
  • new integrations,
  • security recommendations,
  • customer requirements,
  • legal or technical changes.

The current public description of security measures will be available on this page.

22. Contact

For security notifications, vulnerabilities or suspected incidents, please contact us at:

security@profitecom.com

For questions regarding personal data protection: privacy@profitecom.com

General contact: hello@profitecom.com

Operator:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771