Skip to content

Security

How we protect accounts, payments and files.

Last updated: 15 September 2026

1. Principles

  • Role-based access for staff, with only the permissions each role needs
  • Encryption in transit (TLS) on every page
  • We do not collect or store seller provider API keys; credentials used for AI fulfilment are held as server environment secrets and never written to the application database
  • No card numbers or identity documents are stored on GigBlend servers
  • Signed payment webhooks, handled so that a repeated event cannot be applied twice
  • Order files are available only to the people on that order and authorised staff
  • Audit logging of administrative actions

2. Product controls

  • Passwords stored only as salted hashes; sessions expire, and you can sign out of every device from your account page
  • Rate limits on sign-in, sign-up, checkout and other sensitive actions
  • Executable file types are blocked in uploads
  • Automatic flagging of messages that appear to share contact or payment details

3. Infrastructure

The Platform runs on OVHcloud servers in the United Kingdom, and its data is backed up daily.

4. Vulnerability disclosure

Email support@gig-blend.com with a good-faith report. Please do not access other users' data or disrupt the service. We will acknowledge credible reports.

5. Incidents

We investigate incidents and, where personal data is affected, notify the ICO and the people affected as UK GDPR requires.

Questions?

Privacy: privacy@gig-blend.com · Legal: legal@gig-blend.com · See also Contact & company information.

How accounts and files are protected · GigBlend