Security program
Digitdeck maintains a risk-based security program for the application, worker, database, queues, storefront extensions, and operational access. Controls are reviewed as the Service changes.
Core controls
- Shopify OAuth, verified store identity, and minimum required scopes.
- Encryption of offline access tokens and other designated secrets at rest.
- TLS for network connections and managed-provider encryption at rest.
- HMAC verification for Shopify webhooks and signed app-proxy validation.
- Tenant isolation: functional records and queries are scoped to the verified shop.
- Least-privilege production access, named accounts, MFA where supported, and audit logs.
- Rate limiting, input validation, fail-closed plan controls, idempotent jobs, and queue gating.
- Dependency scanning, code review, automated tests, backups, health checks, and incident response.
- No production secrets in source control, client documentation, screenshots, or ordinary logs.
Data classification
| Class | Examples | Handling |
|---|---|---|
| Restricted | Shopify tokens, provider keys, encrypted privacy exports | Encryption, strict access, never client-visible |
| Confidential | Customer email, review/referral records, order/customer identifiers | Tenant-scoped, limited access, redaction |
| Internal | Usage, audit, configuration, support diagnostics | Authenticated access, retention limits |
| Public | Published policies, documentation, approved review content | Integrity and change control |
Retention principles
Digitdeck minimizes collection, retains data only for the stated purpose, and deletes or anonymizes it when no longer required. Customer redaction is executed against customer-linked reviews, back-in-stock subscriptions, referrers, referrals, and related privacy-request records. Shop redaction deletes sessions, audit records for the shop, the shop root, and cascading tenant data.
Exact operational time is controlled by Shopify’s verified privacy events and applicable law. Merchant Data is deleted within the period required by Shopify’s API terms after uninstall or when no longer necessary, normally no later than thirty days unless a lawful exception applies.
Vulnerability reporting
Report suspected vulnerabilities privately to digitdeck.servicios@gmail.com with reproduction steps and impact. Do not access other stores, exfiltrate data, disrupt service, or publicly disclose an unresolved issue. Digitdeck will acknowledge good-faith reports and coordinate remediation.
Incident response
Digitdeck will contain the affected surface, preserve appropriate evidence, rotate affected credentials, determine affected stores and data, remediate the root cause, and notify Controllers, Shopify, regulators, or individuals when contract or law requires. See the DPA for personal-data incident notice.
Business continuity
Managed hosting, database, and queue services provide redundancy and recovery features. Digitdeck tests production builds and critical workflows and maintains recovery procedures. Backup access is restricted; deleted data is not restored into active service except where required for disaster recovery and is re-deleted as the recovery process permits.