Security
Last updated 6 October 2026.
Who is responsible
Flash Listings is run by Flash Software Ltd (company number 17500154). Its director is responsible for security and for this policy, which is reviewed whenever the service changes. Write to owner@flash-listings.com.
Data, encrypted
- Every connection to the site uses HTTPS, enforced with HSTS.
- The tokens that connect your marketplace accounts, and any other stored credentials, are encrypted with AES-256-GCM on our server. They are never sent to a browser.
- The database and its backups are encrypted at rest by our database provider.
- Card payments are taken by Stripe on its own page. We never see or store card numbers.
- We keep only what the service needs. Buyers' names, addresses, emails and payment details are never kept, and uploaded listing photos are deleted after two days. The privacy policy has the full list.
How data is classed
- Secret - marketplace tokens, passwords and keys. Encrypted, held only on the server, never shown to anyone, and replaced at once if exposed.
- Personal - sellers' account details, and the business contacts we email. Encrypted at rest, seen only by the company, and deleted when no longer needed.
- Shop data - listings, photos, orders and figures. Read and changed only for the seller's own shop.
- Public - what sellers publish on marketplaces, and this website.
Our website, server and database all run in the United Kingdom (London). AI services that write listings and make photos receive only the product photos and text they need, and may process them in the United States.
Access
- Everything in a seller's account needs them signed in. Passwords are held by our sign-in provider, never by us.
- Each account's role is checked on the website and again on the server for every request, and each shop's data is only ever read or changed for that shop.
- Administrator access is limited to the company's director.
- Marketplace connections ask only for the permissions the features need, and are used only to do what the seller asks. A seller can disconnect a marketplace at any time, which deletes its stored connection.
The network
- The server runs on isolated virtual machines in London, on a private network, behind our hosting provider's proxy. Only HTTPS is open to the internet.
- It answers only our own website, which proves itself with a secret key on every request. The few services that call in directly, such as payments and marketplace notices, are each checked by their own signature.
- Our hosting providers protect the site against denial-of-service attacks, and our public forms are rate-limited.
- Pages carry a Content Security Policy and refuse to be framed by other sites, and changes requested from other sites are refused.
The software
- Every change is tested automatically before it goes live, with its dependencies checked for known vulnerabilities and the code scanned for leaked secrets.
- Listing descriptions are cleaned on the server before they reach a marketplace.
- The whole service had a full security audit in September 2026, and its findings were fixed.
- Errors are recorded and reviewed, and the server's logs are kept by our hosting provider.
Day to day
- Company computers run antivirus with real-time protection and daily updates (Microsoft Defender).
- They lock after five minutes idle and need a password to unlock, and are kept up to date.
- Every service account - email, code, payments, hosting and the database - has its own strong password, kept in a password manager, and two-step verification.
- Keys for the live service are kept in the hosting platforms' encrypted secret stores, and never put in the code, in email or in chat.
If something goes wrong
- Who: the director leads every incident - containing it, finding the cause, fixing it and telling those affected.
- First: contain it, and revoke and replace any key or connection that may be affected.
- Telling people: sellers whose information is affected, and the marketplaces whose data is involved (such as eBay, Amazon or TikTok Shop), are told without undue delay by email. The Information Commissioner's Office is told within 72 hours where UK law requires it.
- After: what happened and what changed is written down, and this policy updated.
- How to reach us: owner@flash-listings.com or the contact form.
Reporting a problem
Found a security problem? Use the contact form, starting the message with "Security", and say what you found and how to see it. Please do not access other people's data or run automated scans against the live site.