Data Protection & Security
Last updated: October 11, 2026
AttriBolt is built to store as little customer data as possible.
1. What we access and why
- Order details, and the customer's name, email, phone and shipping address on that order, only to show the order on the Thank you and Order status pages and apply the changes the customer confirms. These fields are read and written through Shopify and are not stored in our database.
- We keep an activity log (13 months) with the customer email as a one-way hash, and only the city, region and country of address changes.
2. How we protect it
- Encryption in transit (TLS) and at rest, including backups, by our hosting providers.
- Separate development and production environments and apps; tests run on Shopify development stores.
- Access limited to the people who run AttriBolt, with strong unique passwords and two-factor authentication on every provider account.
- Access to production data is logged by our hosting platform.
- Data minimisation and automatic deletion (see our Privacy Policy for retention periods), and Shopify's privacy webhooks for customer and store deletion.
- No sale or sharing of personal data; no advertising use.
3. Security incident response
- Detect and contain: revoke or rotate affected credentials, disable affected features, preserve logs.
- Assess: what data, which stores, how many customers, since when.
- Notify: affected merchants without undue delay, and within 72 hours of confirming a breach that affects personal data, with what happened, what data was involved, what we did and what they should do. We help merchants with their own notices to customers and authorities.
- Fix and review: remove the cause, verify, and document lessons learned.
4. Report a security issue
Write to support@attribolt.com with the subject "Security".