1. Security Practices
- Encryption in transit: all traffic to and from the App (Shopify Admin API, webhooks, and merchant browsing) is served over TLS.
- Encryption at rest: merchant data is stored in a managed PostgreSQL database (Supabase) with at-rest encryption. Database restores are performed manually from scheduled dumps taken by the operator; an upgrade to the provider's automated daily backups is on the pre-scale roadmap (tracked in the runbook).
- Webhook authenticity: every Shopify webhook is verified with HMAC signatures before processing; requests with invalid signatures are rejected.
- Least-privilege access: the App requests only the scopes it needs (read-only product and order data), and processes the minimum customer data required — for orders, only the destination country code.
- Tenant isolation: data is stored per store and never shared across merchants.
- Access control: the App is maintained by a single developer; infrastructure accounts require strong passwords and multi-factor authentication. Test and production data are kept separate.
2. Monitoring
The production deployment is monitored by an external uptime service with health endpoints (/ping and /health), so outages are detected without relying on merchant reports. Infrastructure and database providers maintain platform-level access and audit logs.
3. Incident Response Process
- Detect & assess (day 0): an incident is identified via monitoring alerts, provider notifications, or reports. The developer assesses scope: what data, which stores, and whether personal data of merchant customers is affected.
- Contain (within 24 hours): affected credentials are rotated, access revoked, or the affected service isolated. If merchant data is at risk, the App can be suspended to stop further exposure.
- Notify (within 72 hours): affected merchants are notified by email with what happened, what data was involved, and what they should do. Where a personal-data breach is likely to result in a risk to individuals, the supervisory authority is notified as required by GDPR Article 33.
- Resolve & verify: the root cause is fixed, data restored from encrypted backups if needed, and the fix verified before returning to normal operation.
- Post-incident review (within 7 days): a written review records the timeline, root cause, and preventive measures, and is retained for accountability.
4. Reporting a Vulnerability
If you believe you have found a security issue in this App, please report it to zhang.rainlam@gmail.com with details and reproduction steps. Please do not test against production merchant data. We will acknowledge reports promptly and keep reporters informed of remediation.