Trust
Security
How we protect merchant and customer data across the EcomGrow apps and our internal systems.
Our approach
Merchants trust us with store data, so security is part of how we design every app. We collect the least data a feature needs, request only the Shopify access scopes we use, and review scopes every time we ship a new feature.
Infrastructure
- Apps run on managed cloud infrastructure with automatic patching and isolated production environments.
- Databases are encrypted at rest with AES-256 and backed up daily. Backups are encrypted and kept for 30 days.
- All traffic uses TLS 1.2 or higher. Shopify webhooks are verified with HMAC signatures before they are processed.
Access control
- Production access is limited to the engineers who need it, protected by single sign-on and multi-factor authentication.
- Access is logged and reviewed every quarter, and removed the same day someone leaves the team.
- Shopify access tokens are encrypted and never exposed to the browser.
Application security
- Code changes are peer-reviewed and tested before release.
- Dependencies are scanned automatically and critical updates are applied quickly.
- Our apps follow Shopify's app requirements, including session token authentication for embedded apps.
Monitoring and incidents
We monitor uptime, errors and unusual activity around the clock. If an incident affects your data, we will notify affected merchants without undue delay, and within 72 hours where the law requires it, with what happened and what we are doing about it.
Report a vulnerability
If you believe you have found a security issue, email support@ecomgrow.co with the subject "Security" and enough detail for us to reproduce it. Please do not access other merchants' data or disrupt our services while testing. We will acknowledge your report within 2 business days and keep you updated until it is fixed.