Is My Data Secure?
Absolutely. Data security is foundational to how Datadrew is built. We understand that you are trusting us with sensitive business data, and we take that responsibility seriously.
Infrastructure Security
Hosted on our cloud infrastructure (our cloud infrastructure): All Datadrew services run on Google Cloud, one of the most secure cloud platforms in the world. Google Cloud maintains SOC 1, SOC 2, SOC 3, ISO 27001, and other industry certifications.
Encryption in transit: All data transmitted between your browser and Datadrew, and between our internal services, is encrypted using TLS (Transport Layer Security).
Encryption at rest: All data stored in our databases and data warehouse (Google our data warehouse, our secure database) is encrypted at rest using AES-256 encryption managed by Google Cloud.
Data Access Controls
Multi-tenant isolation: Each store's data is logically isolated. Queries are automatically filtered by your shop ID so you can only access your own data.
Authentication: Datadrew uses our authentication system Authentication for user sessions and Shopify OAuth for store sessions. All API endpoints require valid authentication.
Role-based access: Team members you invite get access only to the stores and features in your workspace.
Read-Only Shopify Access
Datadrew requests read-only access to your Shopify store. We read your orders, customers, and product data to generate analytics. We never modify, create, or delete anything in your Shopify store.
Third-Party Integrations
When you connect Facebook Ads, Google Ads, GA4, Klaviyo, or Google Search Console, Datadrew uses standard OAuth 2.0 to access your data. Credentials are encrypted and stored securely. You can revoke access at any time by disconnecting the integration in Datadrew or revoking permissions from the platform directly.
What We Do Not Do
We do not sell your data to third parties.
We do not share your data with other merchants.
We do not use your data to train AI models. Drew AI analyzes your data in real-time but does not store your queries or results for model training.
We do not retain your data after you cancel (30-day retention window, then permanent deletion).
SOC 2 Practices
Datadrew follows SOC 2 security practices including access controls, monitoring, incident response, and regular security reviews. Our infrastructure is designed with security best practices from the ground up.
If you have specific security questions or need documentation for your compliance team, contact us at support@datadrew.io.
Related articles
Need help?
If you have questions or run into issues, reach out to us at support@datadrew.io or use the in-app chat. We're happy to help.
