No badges for show. Below is exactly what we do, where the data lives and what we have committed to in writing in the data processing agreement - naming every sub-processor.
GDPR and your customers’ rights
You are the controller of the personal data in your shop, and ZweiHost is your processor. That is not just wording - it is set out in the Data Processing Agreement, which is published and which you can read before you pay rather than on request afterwards.
Data-subject tooling is built in: export of a customer’s data and Article 17 erasure, with an audit record and a grace period.
Deletion requests land in a BackOffice queue so you can action them in time. Orders are not deleted but anonymised, so your accounting record stays complete.
Privacy Policy, Terms, DPA and a data-deletion page - all four are public and bilingual.
On a personal-data breach we notify you without undue delay after becoming aware. You also hold an audit right - annually, or upon an incident.
Where the data lives
Your shop, the admin panel and the database are hosted in the European Union - Railway, EU West region (Amsterdam, the Netherlands). Files and the storefront run through Cloudflare (R2 and Workers). We are specific here because "data in the EU" is easy to write and hard to prove.
Some sub-processors also process data outside the EEA: Stripe (payments), Amazon SES (email delivery) and Sentry (error diagnostics). Those transfers run under the European Commission’s Standard Contractual Clauses or an adequacy decision - we do not claim data never leaves the EU, because that would not be true.
Sentry receives technical error data only: request bodies, cookies, credentials and user identifiers are stripped before anything leaves the server.
The full sub-processor list and their locations are in the Privacy Policy. When one changes we notify you at least 30 days in advance - immediately in the case of an urgent security measure.
Meta and Google are not our sub-processors. For Facebook or Google sign-in they act as independent controllers under their own policies.
Encryption, access and isolation
All traffic runs over TLS, and every shop is isolated at the database level. ZweiHost is a multi-tenant platform: every merchant-scoped table carries a `tenant_id` and every query filters on it - isolation is a property of the schema, not of good intentions.
Passwords are stored hashed, never in readable form. Sensitive secrets (courier, payment and email provider keys) are kept encrypted.
Two-factor authentication (TOTP) - mandatory for platform administrators and available to shop owners. Sessions can be revoked all at once on suspicion of compromise.
Role-based access in the BackOffice: your team sees only what its role allows. Access is controlled and logged.
Every API request carries a correlation id, so a single failed checkout can be traced end to end - without secrets or full customer records being written to the log.
Payments and your certificate
Card details never pass through our servers. A card payment happens at Stripe or Borica, on their own hosted forms - we receive the outcome of the payment, not the card number. It therefore cannot leak from us: we do not store it.
Cash on delivery is collected by the courier and reconciled against orders - with no card details entered anywhere.
Every shop gets a free SSL certificate for its domain, renewed automatically. No add-on fee, and no renewal reminder in your calendar.
The storefront is served over HTTPS only, with HSTS and security headers against framing by another site and content-type sniffing.
Backups and continuity
The database is backed up daily by the managed service, and separately we take a weekly copy at a different provider (Cloudflare R2). That second copy exists precisely for the case where the problem is at the first provider.
Services carry a health check and restart automatically on failure, rather than sitting in a broken state.
On termination we return or delete the personal data - your choice - except where EU or Bulgarian law requires it to be retained.
Yes. All traffic runs over TLS with a free, auto-renewing SSL certificate; each shop’s data is isolated by tenant_id at the database level; passwords are stored hashed, and access is role-based with two-factor authentication. Card details are not stored with us at all - the payment happens at Stripe or Borica.
Where is my shop’s data stored?
The database, the API and the admin panel are hosted in the European Union - Railway, EU West region (Amsterdam, the Netherlands). Files and the storefront run through Cloudflare. Some sub-processors (Stripe, Amazon SES, Sentry) also process data outside the EEA under Standard Contractual Clauses; the full list of locations is in the Privacy Policy.
How is GDPR compliance handled for an online shop?
You are the controller, we are the processor, and the relationship is governed by the published Data Processing Agreement. The platform carries the tooling: export and Article 17 erasure of a customer’s data with an audit record, a deletion-request queue in the BackOffice, anonymisation of orders rather than deletion (so accounting stays complete), a cookie banner and policies built into the shop.
Do you store bank card details?
No. We never see or record a card number. The payment happens on Stripe’s or Borica’s hosted form and we receive only the outcome - success or failure, and an amount. Card data therefore cannot leak from ZweiHost: it does not pass through us.
Do you take backups, and what happens if I delete something?
The database is backed up daily by the managed service and weekly at a separate provider (Cloudflare R2), so it survives a provider-level problem too. If you delete something by mistake, write to us as soon as possible - recovery is from a point-in-time snapshot, so the sooner you tell us the less is lost.
Do you have ISO 27001 or SOC 2 certification?
No, and we do not pretend otherwise. ZweiHost is a small Bulgarian company and that certification is not yet within our reach. What we do have is a published DPA with specific technical and organisational measures, named sub-processors and a written commitment to notify you of a breach. Payments are handled by certified providers.
Order your shop
Like a quick order in your own future shop - the cart is full, and there is nothing extra to pay.