Security

Security and Data Privacy at LiftWize

At LiftWize, we know that your marketing and attribution data is one of your business's most valuable assets. We are deeply committed to the security, integrity, and privacy of the data you process through our platform.

We have architected our systems from the ground up based on modern security frameworks and data privacy best practices.

1. Compliance and Audits

  • SOC 2 Framework: We have designed our platform infrastructure, internal operational controls, and software development lifecycle to meet strict SOC 2 compliance standards. Our formal independent SOC 2 examination is currently underway, and we are awaiting the final audit report completion.

  • GDPR and CCPA: Our products and data pipelines are fully compliant with the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

  • Third-Party Audits: We conduct regular security assessments of our applications and systems. Audit summaries and penetration testing reports can be shared with enterprise clients under a Non-Disclosure Agreement (NDA).

2. Data Processing and Retention

LiftWize operates primarily as a secure data pipeline to feed your marketing dashboards. We prioritize a "data privacy first" architecture:

  • Stateless Processing: We do not permanently store the raw marketing performance data you extract via our connectors. Data only passes through or temporarily lives in a secure cache layer to ensure fast dashboard retrieval, API stability, and reliable performance.

  • Cache Purging: Temporary data storage is automatically purged on a rolling schedule depending on the specific integration requirement. You can always pull fresh, real-time data directly from your ad platforms.

  • Credential Encryption: To fetch data on your schedule or command, we must retain your customer access tokens. These credentials are obfuscated and securely stored using strong AES-256 encryption at rest.

  • Custom Storage Services: If you utilize custom LiftWize data imports or storage features, that data is housed in isolated databases protected by strict role-based access control (RBAC) and full encryption at rest.

3. Data Encryption

Your data is strictly protected both while moving across the web and when stored in our environment.

  • In Transit: All connections between LiftWize services, user dashboards, and account management tools are encrypted by default using industry-standard TLS 1.2 or higher protocols. Any unencrypted traffic (HTTP) is automatically forced to an encrypted channel (HTTPS).

  • Connectors & Destinations: Connections between LiftWize and external advertising APIs (e.g., Google Ads, Meta, TikTok), as well as connections to your data destinations (BI tools, Google Sheets, or data warehouses), are strictly TLS-encrypted.

4. API Permissions and Scopes

We respect the principle of least privilege when interacting with your advertising networks and data destinations.

  • Data Source Permissions: LiftWize utilizes standard OAuth access tokens where possible. This means you grant us access through the ad platform's native login window, and we receive a secure token. We only ever request the absolute minimum read-only permissions required to extract your metrics. LiftWize will never attempt to modify your ad campaigns or account settings.

  • Data Destination Permissions: When pushing data to your destinations (like Google Sheets or custom databases), we only ask for the minimum write privileges needed to deliver your reports. You retain total control and can instantly revoke LiftWize access tokens at any time via the ad platform settings or your LiftWize dashboard.

5. Platform Infrastructure

LiftWize runs on enterprise-grade cloud environments, leveraging the physical and network protections of top-tier cloud providers like Google Cloud Platform (GCP) and Amazon Web Services (AWS).

  • Cloud Security: Our cloud providers maintain world-class compliance certifications, including SOC 1/2/3, ISO 27001, and PCI-DSS.

  • Network Isolation: We isolate our production environment using advanced firewalls, hardened server images, and secure bastion hosts.

  • Access Control: Internal administrative access to LiftWize infrastructure requires Multi-Factor Authentication (MFA), secure VPNs, and strict adherence to the principle of least privilege.

6. Internal Company Policies

Security is an ongoing operational habit at LiftWize, not a one-time setup.

  • Employee Training: All LiftWize employees undergo mandatory information security training upon hire and on a recurring annual basis.

  • Development Practices: Our Software Development Life Cycle (SDLC) includes automated vulnerability scanning, peer code reviews, and formal change management procedures to ensure no insecure code reaches production.


7. GDPR, CCPA, and Data Sovereignty at LiftWize

LiftWize DataStream Limited is compliant under both the GDPR and CCPA. Your data is processed on Amazon Web Services (AWS) and Google Cloud Platform (GCP) servers in the European Union (EU).

Our sub-processors may transfer or process personal data outside the EU/EEA. When personal data is transferred or processed outside the EU/EEA, we ensure that the data is transferred by using the EU Commission’s Standard Contractual Clauses (SCCs) or by other appropriate safeguards as described in Article 46 of the GDPR.

If you have further questions on data sovereignty, do not hesitate to contact us at privacy@liftwize.com.

For more information, please see our Data Processing Agreement (Annex 1 - as part of our Terms of Service), Privacy Policy, and our Sub-processor List.

Contact Our Security Team

If you have any questions, discover a potential vulnerability, or need to request our security documentation, please get in touch with our team directly.

Image

The subscription that pays for itself.

90% of users increase profit during their trial.

Image

The subscription that pays for itself.

90% of users increase profit during their trial.

Image

The subscription that pays for itself.

90% of users increase profit during their trial.