Skip to content

Trust Center

Security & Privacy at Select Security

This page is maintained by Select Security to answer common security and privacy questions about selectsecurity.am. It describes the controls currently enabled in the product. It is editable project content and is not an independent audit or certification.

Shared responsibility. Select Security operates this application on the Lovable Cloud platform. Lovable Cloud provides hosting and managed database, storage, and authentication building blocks. Select Security configures and operates the application on top of them. Customers are responsible for keeping their account credentials secure.

Access & authentication

  • Email & password sign-in with optional Google sign-in.
  • Role-based access: customer, partner, technician, sales manager, manager, and admin. Roles are stored server-side and enforced on every privileged action.
  • Server-side authorization checks for sensitive actions (approvals, role changes, processing transitions), in addition to row-level security at the database.

Platform & hosting

  • Hosted on Lovable Cloud (managed Supabase + edge runtime).
  • Traffic to the application is served over HTTPS.
  • Privileged server-only credentials are kept in platform secret storage and are never shipped to the browser.

Data we collect

  • Account profile: name, email, phone, company, and locale preference.
  • Operational records: quotations, orders, projects, support tickets, and related activity.
  • Files uploaded by staff or customers (e.g. ticket attachments, datasheets).

We use this data to operate the application, fulfil orders, and provide support. We do not sell personal data.

Storage & private files

  • Sensitive buckets (ticket attachments, sales documents, datasheets, manufacturer logos) are private and access-controlled by role.
  • Public buckets contain only assets intended for public display (e.g. product images, reviews).
  • Database tables enforce row-level security; cross-tenant reads are denied by default.

Subprocessors & integrations

  • Lovable Cloud — hosting, database, storage, authentication.
  • Google — optional social sign-in (only when the customer chooses it).

Additional integrations may be added over time. Contact us for the current list before signing a data processing agreement.

Cookies & analytics

  • Authentication uses a session token stored in the browser to keep you signed in.
  • Language preference is stored locally so the UI remembers your choice.
  • We do not run third-party advertising trackers. Any future analytics will be disclosed here before rollout.

Retention & deletion

  • Operational records (quotations, orders, projects) are retained for the life of the account.
  • Customer acceptance records are immutable by design — they form an audit trail of agreed terms and cannot be edited or deleted from the UI.
  • To request export or deletion of your account data, email us at the address below; we will respond within a reasonable timeframe.

Reporting a security concern

If you believe you have found a security issue, please email hayselect@gmail.com. Please do not publicly disclose the issue before we have had a reasonable chance to investigate and respond.

This page describes controls currently enabled in the application. It is not a certification and does not constitute a legal commitment. For approved compliance wording (DPA, subprocessor list, regulatory certifications), please contact us.