Trust centre
Security
Dropship Machine handles your account, your payments and your buyers' delivery details. This page sets out how those are protected, in plain terms.
Last reviewed 14 August 2026
Payments
Payments are processed by PayPal. We never see or store your card number.
- Every payment notification is checked against PayPal's signature before it is acted on. A notification that fails that check is recorded for investigation and never changes your account, your plan or your balance.
- Only a verified notification can claim an event, so a replayed or forged message cannot displace a genuine one.
- Payment endpoints are rate limited.
Pricing integrity
Every price is calculated on our servers from live supplier and delivery data. Prices submitted by a browser are ignored — a modified page cannot change what an item costs, what it sells for, or what you are charged.
Account isolation
Your products, orders, connected stores and billing records belong to your account alone. Every action that touches a record checks ownership on the server, not in the interface. One account cannot read, change, publish or delete another account's data.
Account security
- Passwords are stored only as one-way hashes. Nobody at Dropship Machine can read yours.
- Repeated failed sign-ins lock the account temporarily.
- Your session identifier is replaced when you sign in, so a session cannot be planted in advance.
- Sign-in is available by email, and by trusted providers as each is approved.
- You can delete your account, and the data held with it, from your profile page at any time. Deletion requires your password.
Plan limits
What your plan allows is enforced on the server, inside the same operation that writes the record. Limits are not enforced by hiding a button, and cannot be bypassed by sending requests directly or in parallel.
Infrastructure
- All traffic is served over HTTPS. The site sends strict transport security, content security, framing, content-type and referrer policies.
- The application's database account is limited to its own database, with no server-wide rights.
- Credentials are held in server-side configuration, never in the code repository and never sent to a browser.
- Databases are backed up daily and retained, and restores are tested rather than assumed.
- Operating-system security updates are applied automatically.
- Critical subsystems — payments, supply, background jobs and the scheduler — are checked automatically and raise an alert when they change state.
Your buyers' data
Delivery details reach us only so an order can be fulfilled. They are used for that and nothing else, are never sold, and are not used for marketing. Full detail is in the privacy policy.
Responsible disclosure
If you believe you have found a security problem, please tell us before telling anyone else. Email security@dropshipmachine.com with enough detail to reproduce it.
- We will acknowledge your report within five working days.
- We will not pursue action against anyone who reports a genuine issue in good faith, stays within their own test account, and does not access, change or destroy other people's data.
- Please do not run automated scanning or load testing against the live service.
What we do not claim
Dropship Machine has not yet been through an independent penetration test, and does not hold a formal security certification. The protections above are implemented and tested by us. We would rather say so plainly than imply an assurance we have not earned — this page will be updated when that changes.
Contact
Mando Systems Ltd (company no. 17168657), 10 Pilgrims Walk, Worthing, BN13 1RJ, United Kingdom. General enquiries: hello@dropshipmachine.com.