CatchSync Security & Incident Response
CatchSync is built to hold as little data as possible. This page explains how that data is protected and what we do if something goes wrong. See also the privacy policy.
What we protect
CatchSync stores product and variant prices, inventory quantities, flagged-change history and shop configuration for the stores that install it. It does not access or store customer personal data or order contents.
How we protect it
- Data is encrypted in transit (HTTPS/TLS).
- Minimal access: CatchSync requests only the
write_productsandwrite_inventoryscopes and nothing else. - Webhooks from Shopify are verified by signature before they are processed, and admin requests are authenticated with Shopify session tokens.
- Credentials (API keys, the Shopify app secret, the database password) are kept in the hosting provider’s secret store, not in the code, and are rotated periodically and after any suspected exposure.
- Two-factor authentication is enabled on the accounts that can reach production: hosting, the code repository, the email provider and the Shopify Partner account.
- When a store uninstalls CatchSync, its data is deleted automatically (see the privacy policy).
If an incident happens
- Contain: revoke and rotate any affected credentials, and take the affected component offline if needed.
- Assess: work out which stores and which data were affected, using the app’s logs and database records.
- Notify: if store data may have been exposed, we notify affected merchants by email without undue delay, and within 72 hours of confirming the incident. The notice says what happened, which data was involved, what we have done, and what merchants should do. We also notify Shopify as its Partner terms require.
- Fix and learn: fix the root cause, and publish a short summary of what changed.
Report a vulnerability
If you believe you have found a security problem in CatchSync, please email support@moezeeshop.com with the subject “Security”. Include what you found and how to reproduce it. We will acknowledge your report within 3 business days. Please give us reasonable time to fix the issue before sharing details publicly, and do not access data that is not yours.
Contact
Security questions: support@moezeeshop.com.