Security & data handling at Apptics Suite
What we store, how it's protected, and what happens when you leave.
What we store
- Order data — order totals, line items, currencies, refund amounts, shipping country and method, synced from Shopify to compute profit.
- Customer linkage only, no PII — we store the numeric Shopify customer id to build cohort and LTV analysis. Names, emails, phone numbers, and addresses are never persisted.
- Your cost model — COGS values, variable and fixed cost rules you configure.
- Ad spend — platform-reported daily spend per campaign from the ad accounts you connect.
How it's protected
- All traffic is TLS-encrypted in transit.
- Integration credentials (ad platform tokens, API keys) are encrypted at rest with AES-256-GCM; production keys are KMS-managed.
- Every query is scoped to your store at the data layer — one store can never see another's data.
- We request the minimum Shopify scopes needed: read-only access to orders and products. We never see payment card data (no PCI scope).
Retention & deletion
- Uninstall — synced order data is deleted immediately; Shopify's shop-redaction webhook (48h later) purges everything else: cost rules, ad spend, credentials, tokens.
- Customer redaction — GDPR/CCPA redaction requests sever the customer linkage from orders while keeping your financial reporting intact.
Roadmap
SOC 2 Type II certification is planned. A public status page with uptime history ships when we leave beta. Questions: security@apptics.ai · See also our privacy policy & data processing terms.