SECURITY & TRUST

Clear controls. Clear boundaries.

How WakeMyCart protects account access, connector requests and the recovery workflow.

These are implemented controls, not a claim of independent certification. Production hosting, access management and integration testing remain part of operating the service.

Account access

For optional connected accounts and Pro licensing, passwords are salted and hashed. Sessions use hashed random tokens and HttpOnly cookies. Authenticator MFA supports one-use recovery codes; sensitive account and store changes require reauthentication.

Paired store requests

Minimal account requests authenticate their method, path, timestamp, installation, nonce and exact body with a per-store key. Normal requests exclude shopper records. Connection secrets and MFA material are encrypted at rest.

Email and cart safety

Explicit shopper opt-in, withdrawal, purchase checks and opaque store-hosted restoration links govern eligibility. Message content is escaped. Prepared provider retries retain their exact body and idempotency key.

Update verification

Connected automatic updates check authenticated metadata, the expected HTTPS package origin and the package checksum before installation. Free also supports manual ZIP updates without an account. These automatic verification checks apply to the connected update path.

Data handling

Checkout records and account data have different purposes and retention controls. Encryption of the entire database, backups and host infrastructure depends on the deployed environment; the application does not claim that every field is individually encrypted.

Read the privacy notice and data request guide.

Report a security concern

Describe the affected route/version, impact and safe reproduction steps. Do not send passwords, signing keys, full shopper records or exploit another merchant’s store.

Email the security contact

No public bug-bounty program, audit certification or guaranteed response window is advertised.