INSERTCART AWS WEB · SERVICE INFORMATION

Data handling and privacy

What the new deployment service stores, how temporary sessions expire, and which data remains in AWS.

By InsertCart · Updated 7 October 2026

Sign-in and account metadata

The new service uses Amazon Cognito for sign-in. Your sign-in identity and email are handled by Cognito. The management database stores connections, AWS account identifiers, role ARNs, website names, deployment states, release metadata, and domain settings associated with your signed-in user ID. Alert configuration stores the email address you choose.

Credentials

Guided connections store a role ARN and a unique external ID, rather than your permanent access keys. Advanced IAM user keys are processed to request a temporary session and are not written to the management database. Only temporary session credentials are stored, encrypted with KMS. Their validity is checked before use, and their records expire for background TTL deletion. Refer to the security page for the separate original API flow.

Uploaded content and release history

ZIPs pass through a private staging bucket operated by this service. Staged uploads are eligible for lifecycle deletion after one day; S3 deletion is asynchronous. Website files and completed release prefixes are stored in your own AWS bucket. Those files, earlier releases, and S3 versions remain until you remove them. The three public sample templates are retained as service assets.

Browser storage and logs

The frontend stores sign-in tokens and pending sign-in verification data in session storage for the browser tab. It does not store AWS access keys in browser storage. Signing out clears local sign-in state and credential fields. Refreshing the page does not delete server-side metadata.

Application logging records sanitized operation errors without request bodies or credentials. API access logs record request ID, route, status, and latency. Managed log groups retain entries for 30 days. AWS services may also record security and account activity under their own settings.

Usage measurement

When enabled by the operator, the frontend reports anonymous event categories such as page view, upload selection, connection start, and completed deployment. The management table keeps daily aggregate counts for up to 90 days before TTL deletion. Those event records do not include uploaded files, access keys, page URLs, or user identifiers. These are operational counts rather than unique-visitor analytics.

Disconnecting and removal

Disconnecting deletes the selected connection record; hosting resources and deployment history stay in your account and the management database respectively. Metadata remains until removed by the operator. To ask about removal or this service, use InsertCart’s website. Do not send AWS credentials through a support message.

Ready to publish?

Bring your static website files and connect your own AWS account.

Open the launch workspace ↗

Browse hosting guides · Connection security · Understand costs