How DistroBay handles your data
DistroBay connects to real stores and real credentials, so security isn't an afterthought. Here's a plain-English summary of how we approach it.
Every connected shop uses a secure, standard sign-in connection, so DistroBay never sees or stores your store password. Access tokens are encrypted at rest and scoped to the workspace that created the connection.
Listings generated or edited in DistroBay go to connected shops as drafts by default. Nothing publishes to a live storefront without a person in your workspace reviewing and approving it first.
Workspace access is role-based: only people you invite can see or edit your listings, connections, and settings. DistroBay's infrastructure runs on Firebase and Google Cloud, with data handled in line with standard Google Cloud security practices.
Security FAQ
How does DistroBay store my Shopify credentials?
Connected store tokens are encrypted at rest and scoped to your workspace. We use standard OAuth flows rather than asking for your Shopify password directly.
Can DistroBay publish to my store without my approval?
No. Listings go to your connected shops as drafts by default — nothing goes live without you reviewing and publishing it yourself.
Who can see data inside my workspace?
Only people you've invited to your workspace, with role-based access. We don't share workspace data across other sellers' workspaces.
Where is DistroBay's infrastructure hosted?
DistroBay runs on Firebase and Google Cloud, with functions deployed in an Australian region.
How do I report a security concern?
Email security@distrobay.com with details. We take reports seriously and aim to respond promptly.
Have a specific security question?
Email security@distrobay.com — we're happy to talk through anything before you connect a store.
No spam. Just the future of easier selling for makers.