We ask for less than we could, on purpose.
An SEO app does not need your customers' names, addresses or order contents. We do not request them, so a breach on our side cannot expose them.
Minimum scopes
Products, collections, pages, files and metafields, plus read-only orders for revenue weighting. Nothing else.
No protected customer data
We have never applied for Shopify's protected customer data approval, because we do not need it.
Encryption
AES-256 at rest, TLS 1.3 in transit, with keys rotated quarterly and managed in a dedicated KMS.
Compliance webhooks
All three of Shopify's mandatory GDPR/CCPA webhooks implemented and monitored.
Read-only by default
Auditing never writes to your store. Nothing changes until you apply a fix, and you choose which.
Uninstall cleanly
Removing the app from your Shopify admin ends our access. Shopify's shop/redact webhook then fires and your data is deleted on our side.
Found something? Tell us.
There is no paid bounty programme — we are a new app and we are not going to advertise a reward budget we have not set aside. What there is: a real address that a person reads, and a commitment not to send lawyers at anyone reporting in good faith.
- Acknowledgement within two business days
- We will tell you what we found and when it is fixed
- Public credit in the changelog if you want it
- No legal action for good-faith testing against a store you control
Out of scope
So you do not waste your time — or ours.
- Denial of service, volumetric or otherwise
- Social engineering of our team or of merchants
- Testing against a store you do not own or control
- Missing security headers with no demonstrated impact
- Automated scanner output with no proof of exploitability
- Anything in Shopify's own platform — report those to Shopify
Find something, get paid.
We run a public bug bounty because the alternative is finding out from someone who is not on our side. Good-faith research is welcome and we do not send lawyers at researchers.
- Acknowledgement within 24 hours, triage within 72
- $250 – $5,000 depending on severity, paid on validation
- Public credit in the changelog if you want it
- Safe harbour for good-faith testing against your own test store
Out of scope
So you do not waste your time — and ours.
- Denial of service, volumetric or otherwise
- Social engineering of our team or our merchants
- Testing against a store you do not own or control
- Missing security headers with no demonstrated impact
- Reports generated by an automated scanner with no proof of exploitability
- Anything in Shopify's own platform — report those to Shopify
For your review.
Read and write on products, collections, pages, blogs, files and online-store metafields, plus read on orders so the audit can weight issues by revenue. We do not request protected customer data — no names, addresses, emails or phone numbers — and Shopify's API redacts that by default anyway since API version 2022-10.
All three: customers/data_request, customers/redact and shop/redact. They are declared in our shopify.app.toml compliance_topics and respond 2xx. The shop/redact webhook fires 48 hours after uninstall, and customer redaction completes within 30 days as required.
Audit results and your app settings are stored on our infrastructure, encrypted at rest and in transit. The specific regions and the full subprocessor list are set out on the privacy page — if that page still reads as a template, treat it as incomplete rather than as a commitment.
Affected merchants notified without undue delay and in any case within 72 hours of confirmation, with what happened, what data was involved and what we are doing about it. That is the GDPR standard and it is written into the DPA, not just this page.
No. ShopSEO is a new, small app and we have not been through either audit. Any app that claims a certification should be able to show you the report — ask for it, from us or anyone else.
Read the DPA next.
Named subprocessors, data residency, breach notification and deletion timelines, all in one document.