Skip to content
SproutCart
Security

Data protection and security

How every SproutCart app limits, stores, protects and deletes the personal data of your customers.

Effective 6 October 2026 · Questions or a security report: hello@sproutcart.co

Who decides what

The merchant who installs an app decides why their customers' data is processed. SproutCart processes it only on the merchant's behalf, to provide the app they installed, under the data processing terms every merchant accepts by installing. Each app's privacy page, linked from Support and privacy, lists exactly what that app stores, why, which services see it and when it is deleted.

Only the data the app needs

  • Each app asks Shopify for the narrowest access scopes its features use, and requests protected customer fields (such as email) only where a feature cannot work without them.
  • When an order webhook arrives, the app forwards only the fields its job reads to its background worker. Names, addresses and payment details are dropped at the door.
  • Personal data is used only for the purpose shown on the app's privacy page. It is never sold, rented or traded, never used for advertising, and never sent to an AI service.
  • The apps make no automated decisions that have legal or similar effects on a customer.

Where an app collects data from a shopper directly, such as an email address on a "Notify me" form or a contact form, the shopper submits it themselves for the purpose stated next to the form. The apps send nothing beyond what was asked for, and honour Shopify's customer redaction requests for any customer who asks to be forgotten.

How long data is kept

  • Data is kept only while the merchant uses the app. On uninstall, the app deletes the store's customer data immediately, and deletes it again when Shopify sends shop/redact 48 hours later.
  • When Shopify sends customers/redact, the app deletes everything it holds on that customer.
  • When Shopify sends customers/data_request, the app emails the merchant everything it holds on that customer, so the merchant can answer them.

Where data is stored and how it is encrypted

  • The apps run on Google Cloud Run. Each app has its own Neon Postgres database, which no other app can reach.
  • All traffic is encrypted in transit with TLS: between Shopify, shoppers' browsers and the app, and between the app and its database.
  • Data at rest is encrypted with AES-256 by Google Cloud and by Neon, and so are Neon's backups and restore history.
  • Development and tests use local databases with made-up data. Production data is never copied into a development or test environment.

Preventing data loss and leaks

  • Database credentials and API keys live in Google Secret Manager, never in source code. Each app runs as its own service account, which can read only that app's own secrets.
  • Every webhook from Shopify is verified with its HMAC signature before it is read, and every storefront request with Shopify's app proxy signature.
  • Customer data and email contents are not written to application logs in production.
  • Neon keeps point-in-time restore history for each database, so an accidental change or deletion can be rolled back.

Who can access the data

  • Access to production is limited to the SproutCart operator. Nobody else has an account on the hosting, database or Shopify Partner accounts.
  • Every account that can reach production or store data (Google Cloud, Neon, Shopify Partners, GitHub and the background job service) uses a strong unique password and 2-step verification.
  • Merchants see their customers' data only through the app inside their own Shopify admin, and every such request is logged by Google Cloud with its time and route.
  • Production databases are not queried by hand. The only exception is investigating an incident or a support request from the merchant concerned, and each such access is written into the incident or support record with its date and reason.

Security incident response

When a security incident that may affect personal data is suspected:

  1. Contain. Stop the affected app or revoke the affected credential at once, and rotate every secret that may have been exposed.
  2. Assess. Work out what data, which stores and which customers were affected, using the hosting and application logs, and record the findings.
  3. Notify. Tell Shopify and every affected merchant without undue delay, and within 72 hours of confirming the incident, with what happened, what data was involved and what has been done. Merchants decide how to tell their customers, and get every detail they need to do it.
  4. Fix and review. Fix the cause, confirm the fix, and write down what changed so it cannot happen the same way twice.

To report a vulnerability, email hello@sproutcart.co. A person reads every report.

Audits and certifications

The apps have not been through a third-party security audit or certification.

Changes to this page

When how the apps handle personal data changes, this page changes with it and the date above moves.