Trust
Security
Refit's platform is designed with security, privacy and marketplace trust as core architectural principles. Marketplace credentials, seller data and product content are handled using modern security practices and least-privilege access controls. This page describes the security approach used across the Refit platform.
Last updated · 31 July 2026
Scope
This page describes the security approach for refitplatform.com and the wider Refit platform, including web applications, mobile applications and marketplace integrations operated by Refit. The website is currently informational; the practices below describe how the platform is designed and operated. Refit does not hold any independent certification or audit status.
Authentication
- Users connect marketplace accounts using each marketplace's official OAuth authorisation flow.
- Refit never asks users to enter their marketplace passwords, and does not receive or store them.
- When authorised, Refit securely stores and manages OAuth access tokens using industry-standard security practices to enable approved marketplace interactions.
- Authorisations are revocable by the seller through Refit or the relevant marketplace, where supported.
Data Security
- Data transmitted between users and Refit is encrypted using HTTPS/TLS.
- Sensitive stored data is encrypted at rest.
- OAuth access tokens and other sensitive credentials are encrypted and securely managed.
- Access to sensitive data is restricted to the minimum required to provide Refit's services.
Access Control
- Refit operates according to the principle of least privilege across systems and internal accounts.
- Refit requests only the marketplace permissions necessary to perform authorised functions.
- Production access is restricted and separated from development environments.
Infrastructure
- Refit operates on secure, reputable cloud infrastructure.
- Software and dependencies are updated regularly.
- Systems are monitored for errors, unusual activity and operational issues.
- Industry-standard security practices are followed in the design and operation of the platform.
Privacy
- User data is not sold.
- Customer data is used only to deliver and improve the Refit platform.
- Marketplace data is only accessed and used for actions authorised by the user.
Full detail on collection, retention and user rights is available in our Privacy Policy.
Security Reporting
We welcome reports from security researchers. If you believe you have found a vulnerability, please contact us before disclosing it publicly and give us a reasonable opportunity to investigate and resolve the issue. We will acknowledge legitimate reports and keep you updated on remediation.
Reports can be sent to security@refitplatform.com. Please include steps to reproduce, affected endpoints and any supporting detail. Avoid accessing, modifying or retaining data belonging to other users while testing.
Last Updated
This page was last updated on 31 July 2026.