‹ ShoFinance
Security & Data Protection
Last updated: October 3, 2026
This page describes how WebKoding protects the personal data of merchants' customers that ShoFinance can read through the Shopify API. It complements our Privacy Policy and Terms of Use, which merchants accept when they install or connect ShoFinance.
What customer data we touch
ShoFinance reads, read-only, the customer ID, the customer's order count and the customer name on orders. They are used for one purpose: showing the merchant new vs. returning customers and their top customers. We do not request customer email, phone or address fields, and we never use customer data for marketing, advertising, profiling or automated decisions, and never sell or share it.
Data minimisation and retention
- No server-side storage. The Shopify admin app computes results in memory for each request and discards them. There is no ShoFinance database of orders or customers, so there is no customer data to back up, retain or leak from our servers.
- The only value we write is the merchant's own cost settings, stored in an app-owned metafield inside the merchant's Shopify store, not on our infrastructure.
- The iPhone, iPad and Mac apps keep a cache on the merchant's own device. It is removed when the merchant removes the store in the app, clears the cache, or deletes the app.
- Customer and shop data requests and redaction webhooks (
customers/data_request, customers/redact, shop/redact) are verified by HMAC and acknowledged. Because we hold no customer data, nothing remains to export or delete.
Encryption
- In transit: all traffic between Shopify, our server (Cloudflare Workers) and the apps uses HTTPS/TLS.
- At rest: we store no customer data at rest on our servers. On devices, store access tokens are kept in the system Keychain and cached data stays in the app's sandbox under Apple's data protection.
- Secrets: API secrets and encryption keys are held as encrypted Cloudflare secrets and in an encrypted local keychain, never in source code or plain-text files. Access tokens never travel in URLs.
- Backups: our backups contain source code and configuration only, never customer data, and are stored encrypted.
Data loss prevention
- The architecture is designed so that customer data cannot accumulate: no database, no cache and no logging of order or customer data on our servers.
- Server logs record only technical events (route, store domain, error codes), never order contents, customer names or tokens.
- Test and development use separate Shopify development stores filled with generated test data. Production merchant data is never copied into development or testing.
Access control
- Access to production systems (Shopify Partner Dashboard, Cloudflare, source repositories, Apple developer accounts) is limited to the people who need it to operate ShoFinance. Today that is the founder only.
- Staff accounts require strong, unique passwords stored in a password manager, and two-factor authentication wherever the provider supports it.
- Access to production infrastructure is logged by our providers (Cloudflare and Shopify audit and request logs). Because customer data is not stored on our side, no staff member can browse customer records.
- Credentials are rotated when a person's access ends or when a credential may have been exposed.
Security incident response
If we suspect a security incident affecting ShoFinance, we:
- Contain: revoke or rotate the affected secrets and tokens and disable the affected component.
- Assess: use provider logs to establish what was accessed, when and how.
- Notify: inform affected merchants and Shopify without undue delay, and in any case within 72 hours of confirming a breach involving personal data, as required by applicable law.
- Recover: fix the root cause, redeploy from clean source, and verify.
- Review: record what happened and what we changed so it does not recur.
Contact
Report a security issue or ask a data protection question at support@webkoding.com.