Whipped Studio

Trust centre

Trust, security & privacy

This page is maintained by Whipped Studio to answer common security and privacy questions about our service. It describes the controls currently in place; it is not an independent audit or certification.

Accounts & authentication

  • Sign-in is handled by our managed authentication provider with email/password and Google sign-in.
  • Passwords are never stored by us in plain text — only the authentication provider holds credential material.
  • Administrative privileges are granted through a separate roles table and verified server-side on every request.

Access control

  • Your draft formulations, baskets and orders are only readable by you and by our admin team.
  • Row-level security is enabled on all customer data tables, so authorisation is enforced in the database, not just in the app UI.
  • Order lifecycle changes (submission, status updates) are performed through controlled server actions that re-verify ownership.

Data we store

  • Your account profile (name, optional business name) and the formulations, colours, fragrances and notes you save.
  • Order records including amounts, status and timestamps.
  • We do not store full payment card details — payments, when enabled, are handled by a PCI-compliant payment processor.

Hosting & platform

  • The application runs on managed cloud infrastructure with traffic served over HTTPS.
  • The database, authentication and file storage are provided by a managed backend platform with encryption at rest and in transit.
  • Service-role credentials are kept on the server only and are never shipped to your browser.

Your rights

  • You can request a copy of the personal data we hold about you.
  • You can ask us to correct inaccurate data or to delete your account and associated formulations.
  • For any privacy or data request, contact us at the address below and we will respond within a reasonable timeframe.

Reporting a security concern

If you believe you have discovered a security issue, please contact us privately so we can investigate before any public disclosure. Email hello@whippedstudio.co.uk with the details and steps to reproduce.

This page is editable content maintained by Whipped Studio. It is not an independent certification, audit report, or legal contract. For binding terms, see any separate terms of service or data processing agreement provided to you.