Cloud
Google Cloud and Firebase — Firestore and Realtime Database, Cloud Functions, Firebase Authentication, Cloud Storage and Hosting, plus a MongoDB reporting replica, a Redis cache and a queue for reporting sync.
Written for the person who has to sign off on us. Everything below is something the platform actually does — and the last section answers the five questions every security questionnaire asks.
Google Cloud and Firebase — Firestore and Realtime Database, Cloud Functions, Firebase Authentication, Cloud Storage and Hosting, plus a MongoDB reporting replica, a Redis cache and a queue for reporting sync.
Your tenant runs in the Google Cloud region agreed at provisioning — EU and UK tenants in Europe, others in the region closest to their operations. A tenant is moved only with written agreement.
Per-tenant isolation: every record is stored under your tenant, and database security rules plus server-side middleware check the tenant on every read and write. Dedicated projects are available on enterprise plans.
Firebase App Check — reCAPTCHA v3 on web, Play Integrity on Android, App Attest on iOS — validates that requests come from genuine builds of your apps.
Where card data goes — and how it stays out of our systems.
TLS for every app, API and webhook. HTTPS only.
Google Cloud encrypts databases, storage and backups at rest. Provider secrets are held server-side and are never returned to a browser or app once saved.
Never stored on our systems. Cards are tokenised by your processor, and card-present terminals talk directly to it — which puts the platform out of PCI DSS scope.
The named providers that process data on our behalf. Payment gateways, POS systems, delivery networks and your own SMS or email sender are contracted by you directly, so they are not our sub-processors — those are listed on integrations. Changes are published here; where your agreement includes a sub-processor notice period, it applies.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Application hosting, database and authentication | Your tenant’s agreed project region |
| MongoDB (hosted) | Reporting database behind the analytics endpoints | Region confirmed on request |
| Upstash Redis | Cache and rate limiting | Region confirmed on request |
| Amazon Web Services (SQS) | Queue moving order events to the reporting database | Region confirmed on request |
| Cloudinary | Image storage and delivery for menu and brand assets | Global CDN |
| Sentry | Error monitoring | EU or US, per account configuration |
| Google Maps Platform | Addresses, delivery zones and driver tracking | Global |
| OneSignal | Push delivery, where our platform account is used rather than yours | US |
This website
Netlify (Hosting and form submissions for this website); Crisp (Chat widget on this website); Cal.com (Demo booking widget on this website — the form you fill in to pick a slot); HubSpot (Form submissions and attribution — analytics consent only); Google Analytics (Aggregate traffic measurement — analytics consent only).
You are the controller. These are the tools we give you to act like one.
Managed backups of the primary database, with the retention and restore procedure described on request. Error monitoring scrubs request headers, cookies and bodies, and integration health checks surface provider failures in the admin.
You own your data. Export menus, customers, orders and reports at any time as CSV, JSON or PDF and through the reporting API. After termination your data stays available for export, read-only, for 90 days.
Answered here the way we answer them on the form, so nothing surprises you later in the process.
Certifications
Do you hold SOC 2 or ISO 27001?
The platform runs on Google Cloud, whose infrastructure carries those certifications. SuperApp does not hold a separate report of its own today — and everything an auditor would ask for is written up on this page and in the Data Processing Annex.
Support and availability
Is support 24/7, and is there an uptime guarantee?
Support runs business hours with fast responses across time zones, and response-time targets are written into your contract — a commitment you hold, rather than a marketing availability figure. Planned maintenance is announced in advance.
Card data
Are you PCI DSS certified?
Card data goes from the customer's device straight to Stripe, Finix or your chosen processor — each PCI DSS certified — and never touches our servers. That is what keeps both of us out of PCI scope.
Data protection
Are you GDPR compliant?
Compliance belongs to you as controller, and the platform is built to make it straightforward: consent provenance on every record, erasure that reaches orders and exports, masked exports, and a Data Processing Annex covering us as processor. We call it GDPR-ready, because compliance is a property of how you run it.
Hosting
Are you on AWS or US data centres?
Your tenant runs on Google Cloud in the region agreed at provisioning — EU and UK tenants in Europe — and is moved only with written agreement. One queue component runs on AWS; nothing is placed in the US by default.
Questions, the full Data Processing Annex and the Master SaaS Agreement are available from contact@devkart.com.
Launch food delivery, retail, and more on one white-label platform — live in days.
Book a live demo on a real marketplace · Setup in days