Skip to content
ShopSEO
Security

We ask for less than we could, on purpose.

An SEO app does not need your customers' names, addresses or order contents. We do not request them, so a breach on our side cannot expose them.

Minimum scopes

Products, collections, pages, files and metafields, plus read-only orders for revenue weighting. Nothing else.

No protected customer data

We have never applied for Shopify's protected customer data approval, because we do not need it.

Encryption

AES-256 at rest, TLS 1.3 in transit, with keys rotated quarterly and managed in a dedicated KMS.

Compliance webhooks

All three of Shopify's mandatory GDPR/CCPA webhooks implemented and monitored.

Read-only by default

Auditing never writes to your store. Nothing changes until you apply a fix, and you choose which.

Uninstall cleanly

Removing the app from your Shopify admin ends our access. Shopify's shop/redact webhook then fires and your data is deleted on our side.

Responsible disclosure

Found something? Tell us.

There is no paid bounty programme — we are a new app and we are not going to advertise a reward budget we have not set aside. What there is: a real address that a person reads, and a commitment not to send lawyers at anyone reporting in good faith.

  • Acknowledgement within two business days
  • We will tell you what we found and when it is fixed
  • Public credit in the changelog if you want it
  • No legal action for good-faith testing against a store you control
[email protected]

Out of scope

So you do not waste your time — or ours.

  • Denial of service, volumetric or otherwise
  • Social engineering of our team or of merchants
  • Testing against a store you do not own or control
  • Missing security headers with no demonstrated impact
  • Automated scanner output with no proof of exploitability
  • Anything in Shopify's own platform — report those to Shopify
Bug bounty

Find something, get paid.

We run a public bug bounty because the alternative is finding out from someone who is not on our side. Good-faith research is welcome and we do not send lawyers at researchers.

  • Acknowledgement within 24 hours, triage within 72
  • $250 – $5,000 depending on severity, paid on validation
  • Public credit in the changelog if you want it
  • Safe harbour for good-faith testing against your own test store
[email protected]

Out of scope

So you do not waste your time — and ours.

  • Denial of service, volumetric or otherwise
  • Social engineering of our team or our merchants
  • Testing against a store you do not own or control
  • Missing security headers with no demonstrated impact
  • Reports generated by an automated scanner with no proof of exploitability
  • Anything in Shopify's own platform — report those to Shopify
Security questions

For your review.

Read and write on products, collections, pages, blogs, files and online-store metafields, plus read on orders so the audit can weight issues by revenue. We do not request protected customer data — no names, addresses, emails or phone numbers — and Shopify's API redacts that by default anyway since API version 2022-10.

Read the DPA next.

Named subprocessors, data residency, breach notification and deletion timelines, all in one document.

New on the Shopify App StoreFree plan — no credit card7-day trial on Premium