Security and incident response

Last updated 3 September 2026. Eversogood Web Services Pty Ltd.

What we hold

Deliberately very little. Eversogood Popup writes email addresses straight into your Shopify store and keeps only a masked copy of the last five per shop, so that you can confirm signups are arriving. Everything else we store is counts, settings and your own wording. Your customer list lives in Shopify, which is the record of truth, and losing our entire database would cost you charts and settings, not customers.

How it is protected

What counts as an incident

Any unauthorised access to merchant or shopper data, any loss of that data, any leak of a credential such as an API token or encryption key, and any compromise of the accounts or infrastructure the apps run on.

What happens when one occurs

  1. Contain, immediately. Rotate the affected credentials, revoke tokens, and take the affected surface offline if that is what it takes. Availability comes second to containment.
  2. Assess, within 24 hours. Establish what was accessed, whose data was involved, and whether it is still exposed. Cloudflare and Shopify logs are the evidence.
  3. Notify Shopify within 24 hours of confirming an incident that involves protected customer data, at the contact address on our Partner account.
  4. Notify affected merchants within 72 hours of confirming it, by email, with what happened, what data was involved, what we have done, and what they should do.
  5. Fix and write it up. Close the cause, not the symptom, and record what happened and what changed.

Reporting something to us

If you believe you have found a vulnerability or a breach, email support@eversogoodapps.com with "SECURITY" in the subject. We will acknowledge within one business day. We will not take legal action over good-faith research that does not access other people's data or degrade the service.

Review

This policy is reviewed at least once a year, and after any incident.