PPWR Compliance - Security & Incident Response

Last Updated: September 9, 2026

1. Security Practices

  • Encryption in transit: all traffic to and from the App (Shopify Admin API, webhooks, and merchant browsing) is served over TLS.
  • Encryption at rest: merchant data is stored in a managed PostgreSQL database (Supabase) with at-rest encryption. Database restores are performed manually from scheduled dumps taken by the operator; an upgrade to the provider's automated daily backups is on the pre-scale roadmap (tracked in the runbook).
  • Webhook authenticity: every Shopify webhook is verified with HMAC signatures before processing; requests with invalid signatures are rejected.
  • Least-privilege access: the App requests only the scopes it needs (read-only product and order data), and processes the minimum customer data required — for orders, only the destination country code.
  • Tenant isolation: data is stored per store and never shared across merchants.
  • Access control: the App is maintained by a single developer; infrastructure accounts require strong passwords and multi-factor authentication. Test and production data are kept separate.

2. Monitoring

The production deployment is monitored by an external uptime service with health endpoints (/ping and /health), so outages are detected without relying on merchant reports. Infrastructure and database providers maintain platform-level access and audit logs.

3. Incident Response Process

  1. Detect & assess (day 0): an incident is identified via monitoring alerts, provider notifications, or reports. The developer assesses scope: what data, which stores, and whether personal data of merchant customers is affected.
  2. Contain (within 24 hours): affected credentials are rotated, access revoked, or the affected service isolated. If merchant data is at risk, the App can be suspended to stop further exposure.
  3. Notify (within 72 hours): affected merchants are notified by email with what happened, what data was involved, and what they should do. Where a personal-data breach is likely to result in a risk to individuals, the supervisory authority is notified as required by GDPR Article 33.
  4. Resolve & verify: the root cause is fixed, data restored from encrypted backups if needed, and the fix verified before returning to normal operation.
  5. Post-incident review (within 7 days): a written review records the timeline, root cause, and preventive measures, and is retained for accountability.

4. Reporting a Vulnerability

If you believe you have found a security issue in this App, please report it to zhang.rainlam@gmail.com with details and reproduction steps. Please do not test against production merchant data. We will acknowledge reports promptly and keep reporters informed of remediation.