Security and incident response
Last updated 3 September 2026. Eversogood Web Services Pty Ltd.
What we hold
Deliberately very little. Eversogood Popup writes email addresses straight into your
Shopify store and keeps only a masked copy of the last five per shop, so that you can
confirm signups are arriving. Everything else we store is counts, settings and your own
wording. Your customer list lives in Shopify, which is the record of truth, and losing
our entire database would cost you charts and settings, not customers.
How it is protected
- All traffic is HTTPS. Data is encrypted at rest by Cloudflare, including backups.
- Shopify access tokens are encrypted again by us, with a separate key, before they
are written. A copy of the database on its own cannot act on your store.
- Every database query is scoped to one shop by construction, so one store's data
cannot be read while serving another.
- Every request from Shopify is verified: session tokens, app proxy signatures and
webhook HMACs are all checked before anything is read or written.
- Anything email-shaped is masked in our logs, so an address cannot end up in log
retention by accident.
- Access to your customers is written to an access log you can read inside the app.
What counts as an incident
Any unauthorised access to merchant or shopper data, any loss of that data, any leak of a
credential such as an API token or encryption key, and any compromise of the accounts or
infrastructure the apps run on.
What happens when one occurs
- Contain, immediately. Rotate the affected credentials, revoke tokens,
and take the affected surface offline if that is what it takes. Availability comes second
to containment.
- Assess, within 24 hours. Establish what was accessed, whose data was
involved, and whether it is still exposed. Cloudflare and Shopify logs are the evidence.
- Notify Shopify within 24 hours of confirming an incident that involves
protected customer data, at the contact address on our Partner account.
- Notify affected merchants within 72 hours of confirming it, by email, with
what happened, what data was involved, what we have done, and what they should do.
- Fix and write it up. Close the cause, not the symptom, and record what
happened and what changed.
Reporting something to us
If you believe you have found a vulnerability or a breach, email
support@eversogoodapps.com with "SECURITY" in the subject. We will acknowledge
within one business day. We will not take legal action over good-faith research that does not
access other people's data or degrade the service.
Review
This policy is reviewed at least once a year, and after any incident.