Clear controls. Clear boundaries.
How WakeMyCart protects account access, connector requests and the recovery workflow.
These are implemented controls, not a claim of independent certification. Production hosting, access management and integration testing remain part of operating the service.
Account access
For optional connected accounts and Pro licensing, passwords are salted and hashed. Sessions use hashed random tokens and HttpOnly cookies. Authenticator MFA supports one-use recovery codes; sensitive account and store changes require reauthentication.
Paired store requests
Minimal account requests authenticate their method, path, timestamp, installation, nonce and exact body with a per-store key. Normal requests exclude shopper records. Connection secrets and MFA material are encrypted at rest.
Email and cart safety
Explicit shopper opt-in, withdrawal, purchase checks and opaque store-hosted restoration links govern eligibility. Message content is escaped. Prepared provider retries retain their exact body and idempotency key.
Update verification
Connected automatic updates check authenticated metadata, the expected HTTPS package origin and the package checksum before installation. Free also supports manual ZIP updates without an account. These automatic verification checks apply to the connected update path.
Data handling
Checkout records and account data have different purposes and retention controls. Encryption of the entire database, backups and host infrastructure depends on the deployed environment; the application does not claim that every field is individually encrypted.
Report a security concern
Describe the affected route/version, impact and safe reproduction steps. Do not send passwords, signing keys, full shopper records or exploit another merchant’s store.
Email the security contactNo public bug-bounty program, audit certification or guaranteed response window is advertised.