SHOPIFY APP PRIVACY · EFFECTIVE 11 AUGUST 2026 · VERSION 1.0

Security Statement

A concise description of the privacy and security controls used by Autonomous Commerce Factory.

Security baseline. Least privilege, no normal protected-customer-data dependency, authenticated Shopify privacy webhooks, encrypted secrets, restricted service exposure, encrypted backup handling where configured, and deterministic policy/owner-gate controls for sensitive actions.

Shopify privacy controls

Both Shopify applications subscribe to customers/data_request, customers/redact, and shop/redact. The public receiver uses HTTPS and rejects invalid or missing Shopify HMAC signatures.

Logging and auditability

The system favors minimized, pseudonymous operational/security metadata rather than raw personal-data payloads. Privacy/security evidence can be maintained locally for audit and troubleshooting.

Incident handling

Potential privacy/security incidents are triaged under an incident-response process. Sensitive disclosures, credential changes, financial actions, and other high-impact steps are subject to additional authorization controls.

Report an issue

Email support@echeualdiu.resend.app. Do not include passwords, API secrets, private keys, or unnecessary customer personal data in the initial report.