Security

Security and incident response

This page summarizes the controls used by ProperApp Image Downloader to protect merchant and customer data.

Technical safeguards

The app is designed to reduce exposure of protected customer data.

  • Encryption in transit

    App traffic is served over HTTPS and app proxy requests are sent through secure Shopify storefront endpoints.

  • Encryption at rest for retained customer identifiers

    Customer identifiers stored in download logs are encrypted before being written to the production database.

  • Authenticated admin access

    Merchant staff access the embedded admin only through Shopify-authenticated sessions.

  • Protected data audit trail

    Access to customer-related reporting in the admin is recorded in a dedicated security audit log.

Incident response policy

The app follows a documented response flow when a security issue is suspected or confirmed.

  • Detection and triage

    Review alerts, logs, and merchant reports, then classify severity and affected data.

  • Containment

    Disable affected flows, rotate secrets if needed, and limit access until the issue is contained.

  • Eradication and recovery

    Patch the root cause, validate the fix in production, and restore services in a controlled manner.

  • Communication

    Notify affected merchants and Shopify when required by contract, law, or platform policy.

Security contact

For suspected incidents or urgent data protection questions.