Security and Data Retention
Last updated: July 27, 2026
Controls
Digitdeck uses verified Shopify OAuth, encrypted offline tokens, TLS, webhook HMAC, signed App Proxy requests, tenant-scoped queries, least privilege, rate limiting, idempotent jobs, audit records, backups, secure development review, and incident response.
Retention and deletion
Data is retained only while needed. Valid customer redaction removes customer-linked reviews, back-in-stock records, referrers, referrals, and related requests. Shop redaction removes sessions and cascading tenant data. After uninstall, Merchant Data is deleted within Shopify's required period, normally no later than thirty days absent a lawful exception.
Vulnerabilities and incidents
Report suspected vulnerabilities privately to digitdeck.servicios@gmail.com without accessing other stores or disrupting service. Digitdeck will contain, investigate, remediate, rotate credentials, and notify affected parties where required.