Scope
Owner: SellPrem LLC (the app's developer). Applies to the CODPrem Shopify app and the server that runs it (app.sellprem.com). Reviewed at least once a year.
1. What counts as an incident
Any event where personal data the app holds for merchants (buyer names, phones, emails, addresses, order details, abandoned-lead records) or a merchant's credentials (Shopify tokens, integration keys, ad-account tokens) may have been read, changed or lost by someone or something not entitled to, including: a compromised server or account, a leaked secret, a lost backup, a vulnerability reported by a merchant or researcher, or a Sentry error that shows data reaching a place it should not.
2. Who responds
- Incident lead: the SellPrem LLC owner (contact@sellprem.com).
- Technical lead: the app's developer.
Both are reachable through the support email in the app. Either may declare an incident; the incident lead owns communication.
3. Steps, in order
- Contain within 1 hour of confirmation. Revoke or rotate the affected credential (Shopify app secret, server SSH keys, integration tokens), block the attacking address at the firewall, take the affected process offline if needed. Shopify tokens are expiring and rotate on their own; a compromised one is revoked by reinstalling the app on the shop.
- Preserve evidence. Copy nginx and application logs (
storage/logs), Sentry events and the database backup nearest the event to a separate location before changing anything else. - Assess within 24 hours. Which shops, which people, which fields, over what period. The app's tables are per shop (
shop_domainon every row), so scope is a query, not a guess. - Notify. Affected merchants by email within 72 hours of confirmation with what happened, what data, what we did, and what they should do. Shopify Partner Support through the Partner Dashboard when Shopify data or the platform is involved. Supervisory authorities where the law of the merchant's country requires it (the merchant is the data controller; SellPrem LLC is the processor and supports the merchant's notification).
- Recover. Restore from the last clean backup if data was altered or lost; redeploy from the git repository, never from the compromised host.
- Close. A short written post-mortem: cause, timeline, what changed to stop a repeat. Kept with this document.
4. Controls that limit incidents
- Access to the server and the database is limited to two people, by SSH key
only; no shared passwords; two-factor on Forge, Hetzner, Shopify Partner and Google accounts.
- Personal data is held only as long as it is needed: abandoned leads on a
merchant-set window (7–365 days), fraud rate-limit rows 30 days, and every row for a shop 48 hours after uninstall through Shopify's GDPR webhooks.
- Data in transit is TLS only. Data at rest is encrypted by MySQL
transparent data encryption on the database server; backups are stored encrypted off the server.
- Errors go to Sentry with personal fields scrubbed before they leave the
server.
- Test and production data are separate: development runs on a local
database and a Shopify development store, never against production.
5. Reporting a vulnerability
Email contact@sellprem.com. We acknowledge within 2 working days and do not take action against good-faith reports.