Security

How we protect your store.

Plain answers to the questions merchants and their developers ask us before connecting a store.

Credentials

Shopify and Salla access tokens are encrypted at rest with AES-256-GCM using a key that never leaves our infrastructure. Tokens are never logged, never returned to the browser and never visible to our team.

Permissions

We request the minimum scopes needed to read your catalogue and publish approved changes. We do not request customer, order or payment data.

Change control

Nothing is written to your store without an explicit approval in the Fix Center. Every published batch is recorded with who approved it and can be rolled back.

Data isolation

Every record is scoped to your account. Access checks run on the server for every request; we never rely on the browser.

Hosting

Data is stored in managed, encrypted Postgres databases and served over TLS. Backups are encrypted.

Deletion

Uninstalling the app revokes access immediately. On request we delete your account and all store data.

Reporting a vulnerability

Found something? Write to us through the contact page with details and we'll respond quickly.