Your catalogue is your business. This page describes how we protect it — in plain language, because a security page you cannot understand protects nobody.
Where your data lives
SimplyPIM is hosted in the United Kingdom. Traffic between your browser and the service is encrypted with TLS, and each business's data is scoped to its own account throughout the application — every query runs inside your business's boundary.
Access control
- Roles — owner, editor and viewer roles limit what each member of your team can change.
- Passwords — stored only as salted hashes, never in plain text, with minimum-strength rules at signup.
- API keys — scoped and revocable, so an integration gets exactly the access it needs and no more. AI agents connecting over MCP work under the same scoped keys and roles as humans.
Audit trail
Changes to your catalogue are recorded — who, what, when — so your team can answer "what happened here?" without asking us. Paid feature activations are logged the same way.
Backups
The platform is backed up on a regular cycle, and you can additionally snapshot your own business's data on demand and restore it yourself from the dashboard — recovery is in your hands, not a support ticket.
The storefront pixel
The pixel is deliberately minimal: it reports product views and clicks to your account, sets no advertising identifiers, and cannot read anything else on your shop's pages.
Reporting a vulnerability
If you believe you have found a security issue in SimplyPIM, email security@simplypim.co.uk with enough detail to reproduce it. We read every report, we will not take legal action over good-faith research that respects customer data, and we will credit you if you would like us to.