Where it runs, how it is protected, and what to do if you find a problem. Your business runs through us, so this page states what is in place today rather than what is planned.
The platform, its database and its backups run on a server at Hetzner Online GmbH in Helsinki, Finland. Transactional email leaves through Amazon SES in the United States. The full subprocessor list is in the privacy policy.
TLS in transit on every host, including each shop's own workspace address. Encrypted disks at rest. Backup archives are encrypted before they are stored.
Every record belongs to one workspace and the scope is enforced at the database layer, not by hiding buttons. A request for another shop's record returns a 404, and the assistant can only read the workspace it is asked from.
Role based access (owner, manager, sales, designer, production, finance, viewer). Deactivating a staff member ends their sessions and API tokens immediately. Every record change writes to an append-only activity log.
Taken nightly, checked for freshness each morning, and kept as daily copies for 16 days, then weekly, monthly and yearly copies. Restores are rehearsed against a scratch database so the archive is known to work.
We never see or store card numbers; Stripe handles every payment. Integration credentials a shop pastes in are stored encrypted and shown back masked. SOC 2 readiness work is underway, and we will not claim the badge before a report is issued.
If you have found a security vulnerability in the Printer's Friend platform, please email hello@printersfriend.com. We respond within 24 hours and will not pursue legal action against good faith researchers.