Information Security Policy
Previously published version: June 24, 2026. Read the historical version.
Proposed revision: September 22, 2026. Owner legal and operational review is required before adoption; these revisions are not yet effective in production.
MailPanda (“MailPanda”, “we”, “us”) is an AI email marketer for e-commerce brands. To do that job we are trusted with your account, your brand content, and data about your store’s customers. This policy describes the safeguards — technical, organizational, and procedural — we use to protect that information. It covers mailpanda.ai, app.mailpanda.ai, and the MailPanda integrations (including our Klaviyo and Shopify apps), and it is the security companion to our Privacy Policy. Questions or reports any time: steven@mailpanda.ai.
Our security principles
- Least privilege. Every person, service, and integration gets the narrowest access needed to do its job — and nothing more.
- Tenant isolation. One brand’s data is never used to benefit another and is walled off at the database layer.
- Defense in depth. Encryption, access control, scoped credentials, and monitoring layer on top of one another to reduce reliance on any single control.
- Secure by default. New features inherit our authentication, isolation, and encryption posture rather than opting into it.
Governance & ownership
Security is owned by MailPanda’s engineering leadership, not delegated to a single individual or treated as an afterthought. Access to production systems is restricted to authorized personnel, granted on a need-to-know basis, and reviewed periodically. Security-relevant changes go through code review before they reach production.
Encryption
All traffic between you, your browser, and MailPanda is encrypted in transit using TLS (HTTPS). Data stored in our managed database and object storage (Supabase) is encrypted at rest by the provider. Integration access tokens and other secrets are stored encrypted and are never exposed in client-side code, logs, or URLs.
Authentication & access control
- Managed identity. Sign-in is handled by our authentication provider (Clerk). We never see or store your password. Social sign-in and multi-factor authentication are supported.
- Session security. Private workspace routes check the applicable identity and access on the server. Private Shopify-embedded reads use verified session tokens and linked MailPanda membership; standalone workspace routes use Clerk sign-in. Public integration endpoints, such as storefront capture and webhooks, use route-specific checks rather than requiring a signed-in browser session.
- Role-based access. Within a workspace, access to data and actions is scoped to your account and team. Internal administrative access is limited to authorized staff for support and operations.
Tenant isolation
MailPanda is multi-tenant. Every protected request resolves the signed-in user’s ownership or membership before reading or changing a workspace, and every data operation is scoped to that workspace’s project identifier on the server. A workspace identifier supplied by the browser is never treated as authorization by itself, so one customer cannot reach another customer’s records. Row-level security is enabled on the database as a defense-in-depth backstop; the enforced boundary is server-side authorization plus project-scoped queries.
Integration & token security
When you connect a platform such as Klaviyo or Shopify, we use scoped OAuth wherever the platform supports it — you grant only the permissions a feature needs, rather than handing over master credentials. Access tokens are stored encrypted, scoped to your workspace, and are revocable: disconnecting an integration deletes its tokens. Inbound webhooks from connected platforms (and our own email transport) are signature- or HMAC-verified before we act on them.
Infrastructure & hosting
MailPanda runs on reputable, security-conscious cloud providers in the United States. Our application and APIs are hosted on Vercel; our primary database and storage are managed by Supabase. Synced customer profiles, marketing consent states, order records, and storefront or engagement events are stored in MailPanda, scoped to the connected workspace. Shopify app billing is handled by Shopify; non-Shopify plan payments and existing Stripe subscriptions are handled by Stripe. We rely on these providers’ physical, network, and platform security controls and do not operate our own data centers. We keep dependencies and runtimes current to take up security patches.
Application security
- Changes are version-controlled and reviewed before deployment, with automated type checks, linting, and tests in our continuous integration pipeline.
- Secrets and credentials are managed through environment configuration, never committed to source control.
- We follow least-privilege defaults across services and design new surfaces to inherit our authentication and isolation posture.
Payment security
Shopify app subscriptions are approved and billed through Shopify. Card payments for non-Shopify MailPanda plans and existing Stripe subscriptions are handled by Stripe, a PCI-DSS Level 1 certified payment processor. MailPanda never receives or stores your full card number — we retain only plan, subscription status, and billing references needed to operate billing. Connecting Shopify does not automatically move or cancel an existing Stripe subscription.
AI processing safeguards
MailPanda uses large language and image models to generate marketing content. Depending on the feature and configured provider, prompts, brand content, and reference images are sent through OpenRouter and its model providers, through fal and its model providers, or directly to Google’s Gemini API for image editing, solely to produce your results. We do not train our own models on your data, and we do not permit subprocessors to use your content for advertising.
The current application sends OpenRouter’s data-collection denial setting with its requests, while preserving any stricter zero-data-retention preference. Requests through the shared fal integration opt out of JSON request/response history and request a one-hour expiry for generated media. That expiry does not delete artwork saved separately in MailPanda. Direct Google requests are separate and are not covered by those OpenRouter or fal settings. These are request-level controls, not proof of zero retention, historical deletion, or provider-wide training restrictions. Actual provider accounts, applicable terms, and retention practices still require owner legal and operational verification before this draft is adopted.
Subprocessors & vendor management
We share data only with the service providers that run MailPanda, including Vercel (hosting), Supabase (database & storage), Clerk (authentication), Shopify (Shopify app billing), Stripe (non-Shopify plan payments and existing Stripe subscriptions), PostHog (product analytics), Amazon Web Services (email delivery via SES when you send through PandaSend), OpenRouter and its model providers, fal and its model providers, and Google’s Gemini API (AI generation or editing, as described above). Connected platforms such as Klaviyo and Shopify process data for the integrations you use.
Optional design tools and support services process data only when their features are configured and used. Figma imports can read your connected account details and selected file metadata and designs; explicit exports send selected email designs and assets to Figma. Managed-service onboarding can send merchant contact details, brand names, and setup information to a private Slack channel when Slack provisioning is configured. This draft does not certify that all provider agreements or account settings have been verified. The draft inventory, and how to reach us about it, lives in our Privacy Policy.
Monitoring & logging
We use our hosting and platform providers’ logging and monitoring to detect errors, abuse, and anomalous activity, and to aid investigation if something goes wrong. We aim to log what we need to operate the service securely while minimizing the collection of sensitive data in logs.
Resilience & backups
Our managed database is backed up by the provider to support recovery, and our application is deployed across managed, redundant infrastructure. We rely on our providers’ durability and availability guarantees and design the product to fail safe.
Incident response & breach notification
If we become aware of a security incident affecting your data, we will investigate promptly, take steps to contain and remediate it, and — where a breach is likely to affect you — notify affected customers and any required authorities without undue delay and consistent with applicable law. We will share what we know, what we’re doing, and what (if anything) you should do.
Data retention & deletion
We keep your data while your account is active. Disconnecting an integration deletes its access tokens; “Start over” in Settings deletes your brand workspace. To delete your account and associated data entirely, email steven@mailpanda.ai; we’ll complete it within 30 days, except records we must keep for legal or accounting reasons. Full details are in our Privacy Policy.
Your responsibilities
Security is shared. Please use a strong, unique password (and enable multi-factor authentication), keep your sign-in credentials and connected-platform access secure, invite only trusted teammates to your workspace, and tell us right away if you suspect unauthorized access to your account.
Reporting a vulnerability
We welcome reports from security researchers and customers. If you believe you’ve found a vulnerability or a security issue, email steven@mailpanda.ai with the subject “Security” and enough detail to reproduce it. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn’t yours. We will not pursue legal action against good-faith research conducted under these guidelines.
Changes to this policy
As our practices and infrastructure evolve we may update this policy. We’ll post the new version here and update the effective date — and for significant changes, we’ll notify you by email or in the product.
Contact
MailPanda · steven@mailpanda.ai
