Security & Compliance
How we protect your data and your unreleased imagery.
ShotSync turns raw fashion shoots into channel-ready product listings. Here are the security controls and data-handling practices we operate today.
Your imagery stays on your device
Pre-launch shoots are clustered, renamed and formatted in your browser — not uploaded to our servers as part of the workflow.
Every brand is isolated
Every query is scoped to the caller’s organisation, enforced in the application layer and backed by an automated check that runs on every code change.
Built on audited infrastructure
Every layer runs on SOC 2 Type II–certified providers — Supabase, Vercel and Stripe — so we inherit their controls.
We never touch card data
Payments run entirely through Stripe (PCI-DSS Level 1). ShotSync never sees, transmits or stores card details.
How we handle your data
Security controls
Sub-processors
| Provider | Purpose | Data handled | Compliance |
|---|---|---|---|
| Supabase | Database, authentication & file storage | Account & product data | SOC 2 Type II |
| Vercel | Application hosting, CDN & edge | Requests & operational logs | SOC 2 Type II |
| Stripe | Payment processing | Billing details (no card data stored by ShotSync) | PCI-DSS L1 · SOC 2 |
| Anthropic | AI product copy generation | Product attributes & prompts | SOC 2 Type II |
| OpenAI | Accessory category detection from images | Low-resolution product image crops | SOC 2 Type II |
| Replicate | Background removal (when enabled at export) | Product images you select | SOC 2 Type II |
| PhotoRoom | Background removal at higher volumes | Product images you select | GDPR compliant |
| Resend | Transactional email | Name & email address | SOC 2 Type II |
| Cloudflare | Bot protection on sign-in and sign-up | IP address & browser signals | SOC 2 Type II · ISO 27001 |
| Sentry | Error monitoring | Diagnostic data (PII-scrubbed) | SOC 2 Type II |
Our current sub-processor list. A signed Data Processing Agreement (DPA) is available on request — email hello@shotsync.ai.