‹ ShoFinance

Security & Data Protection

Last updated: October 3, 2026

This page describes how WebKoding protects the personal data of merchants' customers that ShoFinance can read through the Shopify API. It complements our Privacy Policy and Terms of Use, which merchants accept when they install or connect ShoFinance.

What customer data we touch

ShoFinance reads, read-only, the customer ID, the customer's order count and the customer name on orders. They are used for one purpose: showing the merchant new vs. returning customers and their top customers. We do not request customer email, phone or address fields, and we never use customer data for marketing, advertising, profiling or automated decisions, and never sell or share it.

Data minimisation and retention

Encryption

Data loss prevention

Access control

Security incident response

If we suspect a security incident affecting ShoFinance, we:

  1. Contain: revoke or rotate the affected secrets and tokens and disable the affected component.
  2. Assess: use provider logs to establish what was accessed, when and how.
  3. Notify: inform affected merchants and Shopify without undue delay, and in any case within 72 hours of confirming a breach involving personal data, as required by applicable law.
  4. Recover: fix the root cause, redeploy from clean source, and verify.
  5. Review: record what happened and what we changed so it does not recur.

Contact

Report a security issue or ask a data protection question at support@webkoding.com.