Your business data protected using industry-standard practices. Not marketing claims — actual implementation you can verify.
Why security matters to us
When you connect your Etsy shop, Shopify store, Instagram, and Pinterest to Northflo, you are trusting us with access to your business. This page explains exactly how we protect your data, how marketplace connections work, and what happens if something goes wrong.
For specific questions, contact security@northflo.com and we will answer directly.
Technical security measures
HTTPS everywhere — every connection to Northflo uses TLS encryption.
Encrypted data storage — marketplace tokens, personal information, and account credentials are encrypted at rest.
Secure authentication — passwords are never stored in plain text, and two-factor authentication is available on every plan.
Access controls — only the services and people who need specific data can access it, with access logged and monitored.
Regular reviews and recovery — infrastructure, code, dependencies, backups, and recovery procedures are continually reviewed.
Marketplace authorisation
Every marketplace connection uses OAuth 2.0, the industry standard for secure third-party access. You sign in through each platform’s own login flow; Northflo never sees, asks for, or stores your marketplace passwords.
Northflo requests only the permissions needed to read and manage listings, sync inventory, and track orders. Authorisation tokens are encrypted at rest, and you can disconnect a marketplace at any time from Northflo or directly from the marketplace account.
How we handle your data
You own your data. Northflo processes it only to provide the service you signed up for. We collect only what is necessary, never sell your data, never share listing data with advertising networks, and never use your business content to train external AI models.
You can export your data as CSV at any time. You can delete individual items, categories, or your whole account. Deletions are permanent after a 90-day recovery window.
Regulatory compliance
Northflo is built to support UK and EU GDPR requirements: lawful processing, data minimisation, purpose limitation, access, correction, deletion, portability, objection rights, and timely breach notification.
Our integrations use official marketplace authorisation methods and are designed to align with Etsy, Shopify, Instagram, and Pinterest developer terms.
What happens if something goes wrong
Northflo infrastructure is monitored continuously, with automated backups and recovery procedures in place. If a security incident occurs, affected users will be notified promptly in line with GDPR requirements.
If Northflo were ever to shut down, we would give customers 90 days’ notice and provide full data export capabilities.
Security questions
For security questions, contact security@northflo.com. For data protection questions, contact privacy@northflo.com. We respond within 48 hours, or within 24 hours for suspected incidents.