Simplebooklet Data Encryption Overview
Simplebooklet Data Encryption Overview
Simplebooklet Marketing Inc. | Effective December 1, 2024
Purpose
This document outlines how Simplebooklet encrypts and protects customer data across all layers of its platform — including transport encryption (SSL/TLS), custom domain certificate management, and storage encryption within our hosting infrastructure.
Our goal is to ensure data confidentiality, integrity, and authenticity throughout the lifecycle of every booklet and user interaction.
1. Encryption in Transit
1.1 Standard SSL/TLS Encryption
All data transmitted between users, readers, and Simplebooklet's servers is protected using TLS 1.2 or higher encryption protocols.
This includes:
- Data uploaded through the Simplebooklet web app (e.g., PDFs, images, designs)
- Reader sessions viewing published booklets
- Administrative dashboard traffic
- API communication between services (Customer.io, Paddle, ProfitWell, etc.)
Every Simplebooklet URL is automatically served over HTTPS, ensuring that no data — including authentication tokens, analytics events, or media — is ever sent in plaintext.
1.2 Wildcard Certificates for Custom Domains
For customers using custom branded domains (e.g., brochure.yourcompany.com), Simplebooklet issues and manages Wildcard SSL Certificates through a trusted Certificate Authority.
- Certificates are generated, renewed, and validated automatically using Let's Encrypt Wildcard SSL (via DNS-based verification).
- This ensures every custom domain benefits from end-to-end HTTPS coverage without requiring manual certificate installation.
- Wildcard certificates are stored in encrypted form within our secure infrastructure and rotated regularly.
Example:
https://marketing.acmebrochure.com
→ protected via *.acmebrochure.com wildcard certificate
→ handled through Simplebooklet's secure SSL termination and CDN edge servers
2. Encryption at Rest
2.1 File and Data Storage
All data stored within Simplebooklet's hosting environment (Liquid Web) is encrypted at rest using AES-256 industry-standard encryption algorithms.
This includes:
- Uploaded documents, images, and assets
- Generated previews and metadata
- Reader engagement logs and analytics data
- Account credentials and configuration data (hashed and salted)
2.2 Backup and Redundancy
Nightly backups of data and configuration are:
- Encrypted using AES-256 before replication
- Stored in separate secure environments within Liquid Web
- Retained only as long as necessary for operational recovery (max 30 days)
Encryption keys are securely managed by Liquid Web's key management systems and are never exposed to Simplebooklet employees or third parties.
3. Certificate and Key Management
- SSL/TLS certificates (both standard and wildcard) are renewed automatically every 90 days.
- Private keys are stored in restricted-access directories within encrypted Liquid Web storage volumes.
- Administrative access to certificate systems is restricted to authorized DevOps personnel only, using MFA and RBAC policies.
- Key rotation and decommissioning procedures are logged and reviewed quarterly.
4. Compliance and Best Practices
Simplebooklet's encryption practices align with recognized security standards including:
- NIST SP 800-57 (Key Management Best Practices)
- ISO/IEC 27001:2022 (Information Security Management)
- GDPR & PIPEDA encryption expectations for protecting personal data
All encryption protocols and certificate management workflows are reviewed annually as part of our security and privacy policy updates.
Summary
Through the use of Wildcard SSL certificates, TLS-encrypted transport, and AES-256 encrypted storage, Simplebooklet ensures that every customer asset — from uploaded documents to reader sessions — remains secure, authenticated, and private throughout its lifecycle.
Updated on: 08/09/2026
Thank you!
