Data Security

Last updated: June 28, 2026

1. Our Commitment

Appziot (“we,” “our,” or “us”) is committed to protecting merchant, customer, and platform data. This Data Security page describes the technical and organizational measures we use to safeguard information processed through our Shopify app, admin dashboard, APIs, and merchant mobile applications.

2. Encryption and Transport Security

All data exchanged between merchants, customers, mobile apps, and Appziot services is transmitted over HTTPS using Transport Layer Security (TLS). We maintain valid TLS/SSL certificates on our production domains, including:

  • Merchant admin dashboard and embedded Shopify app surfaces
  • Public APIs used by mobile applications
  • Webhook endpoints that receive events from Shopify and other integrated services

Sensitive data stored in our systems is encrypted at rest using industry-standard encryption provided by our cloud infrastructure providers.

3. Authentication and Access Control

We protect access to Appziot systems through multiple layers of security:

  • Shopify OAuth for merchant installation and re-authentication
  • Session tokens for embedded admin experiences, consistent with Shopify App Bridge requirements
  • Role-based access controls for internal administrative tools
  • Principle of least privilege for production system access
  • Secure credential storage for API keys and integration secrets

4. Shopify Platform Security

Appziot is built as a Shopify app and follows Shopify platform security expectations, including:

  • Requesting only the API access scopes required to deliver app functionality
  • Processing billing exclusively through Shopify App Pricing and the Shopify Billing API
  • Subscribing to mandatory compliance webhooks for customer and shop data requests and redaction
  • Handling app uninstall and data-deletion workflows in accordance with Shopify requirements
  • Not storing Shopify access tokens or merchant credentials in client-side browser storage

5. Payment and Billing Security

Appziot does not collect or store merchant payment card details. Subscription and usage-based charges are processed through Shopify’s billing infrastructure and appear on your Shopify invoice. Appziot does not operate a separate payment gateway for app subscriptions.

6. Infrastructure and Monitoring

Our production environment is designed with security and reliability in mind:

  • Hosted on reputable cloud infrastructure with network-level protections
  • Automated monitoring for service health, errors, and anomalous activity
  • Regular software updates and dependency maintenance
  • Logical separation between production and non-production environments
  • Backup and recovery procedures for critical application data

7. Third-Party Service Providers

Appziot uses carefully selected subprocessors to deliver core functionality. These providers are contractually required to maintain appropriate security standards. Key categories include:

  • Shopify — commerce platform, APIs, and billing
  • Cloud hosting and database providers — application infrastructure
  • Push notification providers — delivery for merchant mobile apps
  • Analytics and operational monitoring tools — service performance and reliability

For details on what data is shared with these providers, see our Privacy Policy.

8. Data Minimization and Retention

We collect and retain only the data necessary to operate Appziot services. When you uninstall the app or submit a valid deletion request, we delete or anonymize applicable data within a reasonable period, subject to legal retention obligations. See our Privacy Policy and GDPR page for retention and deletion details.

9. Incident Response

We maintain procedures to detect, investigate, and respond to security incidents. If we become aware of a data breach that affects your information and is subject to notification requirements, we will notify affected merchants without undue delay and in accordance with applicable law.

10. Merchant Responsibilities

Merchants also play an important role in keeping data secure. You are responsible for:

  • Maintaining the security of your Shopify admin and Appziot account credentials
  • Granting only the permissions your team members need
  • Ensuring your mobile app privacy policy accurately describes data practices for your customers
  • Complying with applicable privacy laws for data you collect through your store and mobile app
  • Using Apple and Google developer accounts and platform tools in accordance with their security requirements

11. Reporting Security Concerns

If you discover a security vulnerability or have a security-related concern, please contact us immediately at support@appziot.com with the subject line “Security Report.” Please include sufficient detail for us to investigate.

12. Contact Us

For questions about our data security practices:

Email: support@appziot.com
Address: India