linkrra
Security
How we protect your data. Last updated: 3 August 2026.
All in reads your business data to compute analytics — so protecting it is the product, not an afterthought. Here is exactly how.
Read-only access
We ask only for read/analytics scopes at each provider. We never request write access to your store, ads, or email.
Encrypted at rest
Connector credentials are encrypted with AES-256-GCM before they touch the database, and decrypted only in memory during a sync.
Per-tenant isolation
Postgres row-level security: every query is scoped to your account. One customer can never read another's rows.
Least-privilege DB role
The app connects as a restricted, non-superuser role that cannot bypass row-level security.
Signed sessions
Read access requires an HMAC-signed session token bound to a single tenant. Everything is served over HTTPS.
Revoke anytime
You can disconnect any connector or delete your account and all data at any time.
Minimum scopes we request
- Shopify — read_orders, read_products, read_customers, read_inventory
- Meta Ads — ads_read
- Google Ads / GA4 — read-only reporting
- Klaviyo — read
- QuickBooks / Xero — accounting.read
- Gmail / Drive — readonly
Sub-processors
We use a small set of vetted providers to run the Service. They process data on our behalf under their own security terms.
| Provider | Purpose | Location |
| Supabase (Postgres) | Encrypted application database | AWS ap-northeast-1 |
| Netlify | Static site & edge delivery | Global CDN |
| Vultr | Application server (backend) | EU (Frankfurt) |
| AI model provider | Generates copilot answers from your metrics | Contracted, no training on your data |
| Stripe | Subscription billing (card data never touches our servers) | Global |
Data processing & deletion
We keep your data only while your account is active and delete it within 30 days of a deletion request. We do not sell your data or use it to train third-party AI models. A Data Processing Addendum (DPA) is available on request for business customers.
Report a vulnerability
Found something? Email weare@linkrra.com and we'll respond quickly. Please give us a reasonable window to fix before public disclosure.
← Back to Linkrra All in