Data security in Picqer
You store data about your business and your customers in Picqer. We take the security of that data very seriously. On this page you can read which measures we take to protect your data, and what you can set up yourself to make your account even more secure.
What Picqer does
- Hosting with ISO-certified providers. Picqer runs on Amazon Web Services (AWS) infrastructure, which is ISO 27001, SOC 1 and SOC 2 certified, among others. We exclusively use hosting providers with these certifications.
- Your data stays in Europe. All data is stored in data centers within the European Economic Area.
- Encrypted connections and storage. All connections with Picqer are encrypted, for example between your online store and Picqer, between Picqer and shipping carriers, and through the API. We store personal data encrypted where possible, and our backups are encrypted as well.
- Regular independent testing. Our code and infrastructure are regularly tested independently, including penetration tests by external security specialists.
- Automated security checks. All new code that goes to production passes automated security checks, such as scans for vulnerabilities and leaked credentials. Measures like these are also required from us by platforms such as bol and Amazon.
- Strict access control within the Picqer team. Within Picqer, access to customer data is strictly limited to employees who need it for their work. Our employees always log in with two-factor authentication, and access to systems is logged.
- Incident response and breach notifications. We have a strict incident response procedure. Should something go wrong despite all measures, we will notify you quickly, in line with the agreements in the data processing agreement.
- Responsible disclosure. Security researchers can safely report vulnerabilities to us through our responsible disclosure program.
The agreements about the security of your data are laid down in the data processing agreement that all customers sign with us. You can find an up-to-date overview of our processors and subprocessors on the processors page.
What you can do yourself
Besides the measures we take, you control who has access to your account and which data you keep. This limits the impact if something ever does go wrong, for example if one of your users' passwords leaks.
- Require two-factor authentication for all your users. With two-factor authentication, someone with just a leaked password can never log in to your account.
- Set up trusted IP addresses. With trusted IP addresses, users can only log in from locations you approve, such as your office or warehouse.
- Give users only the access they need. With user permissions you control exactly what each user can see and do. Deactivate users immediately when they leave your company.
- Be careful with API access. Only give API keys to parties you trust and with whom you have made the same data protection agreements as with your own customers. Use a separate API key for each integration and delete keys you no longer use.
- Anonymize data you no longer need. Orders that were shipped more than 7 days ago can be anonymized. You can do this per order through the interface, or automatically through the API. Your sales reports will keep working as usual.
- Keep an eye on the audit log. The audit log shows all events relevant to information security, such as exports of customer data and changed login credentials.
Questions about security?
Do you have questions about data security? Please contact our support team. Think you have found a vulnerability? Report it through our responsible disclosure program.


