Security & compliance.
Convertly handles your store data, your creators’ details, and real money. Here’s how we protect all three — and what we’re continuing to build.
Shopify-native authentication
We use Shopify’s managed installation and token-exchange flow — no passwords to manage. Access tokens are encrypted at rest (AES-256-GCM) and used only for the scopes you grant.
Encrypted sensitive data
Tax identifiers (e.g. W-9 SSN/EIN) and payout credentials are encrypted at rest. We never expose them through the API, and we collect only what payouts and compliance require.
Verified webhooks
Every Shopify webhook is verified with HMAC signatures and de-duplicated against replays, so order and commission events can be trusted end to end.
Auditable, immutable ledger
Commissions are recorded in an append-only ledger and every agent or human action is written to an audit log — so money movement is always traceable and reconcilable.
Privacy & data rights
We honor Shopify’s GDPR webhooks (customer data request, customer redact, shop redact) and support data export and deletion. See our Privacy Policy for details.
Data safety by design
Soft-deletes across records prevent accidental data loss, and infrastructure runs on managed, reputable providers (Shopify, Vercel, Neon, Railway, Cloudflare).
Compliance & global payouts
Convertly supports multi-currency payouts and handles country-specific tax requirements, including India TDS withholding (with year-end statements). We're an early-stage company and are transparent about our roadmap: formal third-party certifications (e.g. SOC 2) are not yet in place — if you have specific compliance requirements, talk to us and we'll share where we are.
Report a vulnerability
Found a security issue? We want to hear from you. Email security@convertlyhq.com and we'll respond quickly. Please give us a reasonable window to remediate before public disclosure.
Your AI growth team is one install away.
Find creators, turn your own customers into them, and run the whole program from one place. Install free — you only pay when creators drive revenue.