Security & privacy.
Your creator program depends on store data, personal information and reliable financial records. Here are the controls behind the workspace.
Shopify-native authentication
The Shopify integration uses managed installation and token exchange. Stored access tokens use AES-256-GCM application encryption. Portal accounts have their own authentication and access controls.
Encrypted sensitive data
Sensitive tax identifiers and integration credentials use application-level encryption. Authorized workflows expose masked details instead of returning stored secrets for display.
Verified webhooks
Shopify webhook handlers verify HMAC signatures. Order-processing safeguards help prevent repeat events from creating duplicate commission records.
Commission records and audit trails
Commission ledger entries and audit events record important changes and supported agent actions. They help your team investigate activity and reconcile earnings with payment records.
Privacy & data rights
The Shopify integration receives privacy-request webhooks. Export and deletion requests may require follow-up processing; contact privacy@convertlyhq.com to exercise your rights or coordinate a merchant request.
Data safety by design
Applications and data run on managed infrastructure including Vercel, Railway, Neon and Cloudflare. Access checks separate brand workspaces and limit operations by account role.
Security reviews
Convertly does not currently hold SOC 2 certification. If your team needs a security questionnaire, data-processing terms or details about a specific control, contact security@convertlyhq.com before onboarding. Privacy rights and request channels are described in our Privacy Policy.
Report a vulnerability
Found a security issue? We want to hear from you. Email security@convertlyhq.com and we'll respond quickly. Please give us a reasonable window to remediate before public disclosure.
Bring your creator program together.
Start on Shopify, or walk through your current setup with us.