Security at Modovisa
How we protect customer accounts and visitor analytics data across our Cloudflare-hosted stack.
Infrastructure
Modovisa runs on Cloudflare Workers, Pages and D1. Traffic is served over HTTPS with modern TLS, and the application layer runs at the edge rather than on servers we patch by hand.
Access and accounts
Account access uses authenticated sessions with optional two-factor authentication. Internal tooling is behind role-based admin permissions, so administrative capability is scoped rather than shared.
- Authenticated sessions with optional 2FA
- Role-based permissions for internal admin tools
- Account and data deletion available to customers directly
Data handling and retention
Retention follows your plan: 30 days on Free, unlimited on paid plans. Our Privacy Policy sets out what is collected and why, and the Data Processing Agreement covers controller and processor responsibilities for customers who need one on file.
- Privacy Policy — /legal/privacy-policy
- Data Processing Agreement — /legal/dpa
- Delete account and data — /legal/delete-account
Reporting a problem
If you believe you have found a security issue, email [email protected] with enough detail to reproduce it. We would rather hear about it early than read about it later.
Frequently asked questions
Where is Modovisa data processed?
On Cloudflare's platform — Workers, Pages and D1. The Privacy Policy and DPA describe processing and responsibilities in detail.
Is a DPA available?
Yes, at /legal/dpa, for customers who process personal data through the platform.
How long is analytics data kept?
30 days on the Free plan and unlimited on paid plans. Account and data deletion is self-serve.
Is two-factor authentication supported?
Yes, 2FA is available on accounts.