Security at Progus

Last updated: 26.09.2026

This page is for merchants and their security teams reviewing a Progus application. It summarises how we protect data; the binding terms are in our Data Processing Agreement (Annex II lists the technical and organisational measures, Annex III the sub-processors) and our Privacy Policy.

Company

Progus sp. z o.o., ul. Sklepowa 27, 97-500 Radomsko, Poland (KRS 0001078024, NIP 7722434496). We are established in the European Union and subject to the GDPR. For your store's customers and visitors we act as a processor on your behalf; for your own merchant account we act as controller.

Infrastructure

  • Databases on Amazon Web Services RDS (United States), encrypted at rest with AES-256 (keys in AWS KMS).
  • Application servers on Heroku (United States) and Fly.io (European Union, United States), with Cloudflare for content delivery and protection. The location of each application's servers is listed in Annex III of the DPA.
  • All of these providers hold independent security certifications (such as ISO 27001 and SOC 2).
  • Automated daily database backups, encrypted, kept for 35 days for Progus Store Locator and 7 days for the other applications, then deleted automatically.
  • Server logs are kept for a limited period: 7 days on Fly.io, and in Better Stack 15 days for Progus Store Locator and 8 days for its storefront API. Cloudflare does not keep request logs. Error reports from the Store Locator map (Sentry) are stored in the EU for up to 90 days, without user details, cookies or form contents.

Encryption

  • All traffic to our applications and storefront widgets uses HTTPS (TLS).
  • Data in our databases and backups is encrypted at rest.

Access

  • Access to production systems and databases is limited to the managing director and the employees who need it for their work, and removed on the day a person leaves.
  • Two-factor authentication on all administrative accounts (hosting, source code, Shopify Partner account).
  • Shopify access tokens are stored server-side only and are never sent to the browser.

Data protection

  • We handle Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact).
  • When you uninstall Progus Store Locator, Subscriptions, InPost, AI Studio, COD Form, Upsell or Trust Badges, we delete your store's data; the deletion completes at the latest when Shopify sends shop/redact, 48 hours later. Backup copies expire within 35 days.
  • Progus Sticky Add to Cart does not store personal data of your customers.
  • We do not sell personal data and do not use your store's data to train AI models.
  • Sub-processors are listed in Annex III of the DPA, per application, separately from the integrations you connect with your own accounts. We announce changes at least 14 days in advance by e-mail to every merchant who signed the DPA online and in the DPA version history.
  • You can sign the DPA online at progus.com/dpa/sign and receive the signed PDF by e-mail.

Incidents

We follow a written incident response procedure. If a personal data breach affects data we process on your behalf, we notify you within 48 hours of becoming aware of it, and we notify the supervisory authority within 72 hours where the law requires.

Certifications

Progus itself does not currently hold ISO 27001 or SOC 2 certification. Our hosting and infrastructure providers do. We are happy to answer security questionnaires; write to privacy@progus.com.

Reporting a vulnerability

If you believe you have found a security issue in a Progus application or website, please write to privacy@progus.com with the details and steps to reproduce. Please give us reasonable time to fix it before disclosing it, and do not access or change data that is not yours. We reply to every report. Our security.txt follows RFC 9116.