Security · Access · Deletion
Security and data handling, stated plainly.
How does Kaupvik Quick Order handle security?
It reads products, B2B company context and the minimum customer fields needed to pick a purchasing contact, then creates a Shopify draft order once a person confirms the reviewed lines. It does not request write access to products, customers, companies or orders. Development and production run as separate apps, deployments and databases, and no production merchant data is processed today because the app is not launched.
The model in one screen
Read little, let Shopify decide, write one thing.
Read what the task needs
Products and variants, companies and locations, and the minimum customer fields needed to choose a purchasing contact. Nothing else is requested.
Let Shopify decide
Prices and availability are computed by Shopify for the selected company location. Kaupvik has no pricing engine and does not override catalog rules.
Write one thing, after a person confirms
Every write follows an explicit confirmation in the review workspace, and the result is a draft order your team continues in Shopify.
Data is limited to what the workflow and troubleshooting require. The app does not collect storefront browsing data, does not process payment details, and does not sell or share merchant data.
Access scopes
The exact Shopify access the app requests, and the access it refuses.
| Scope | Requested | What it reaches, and why |
|---|---|---|
| read_products | Yes | Products and variants, so each line of a list matches a real variant and candidates can be offered when nothing matches exactly. |
| read_companies | Yes | Companies, company locations and purchasing contacts, so a list is reviewed in the buying context you select. |
| read_customers | Yes | Only the minimum customer fields needed to select a purchasing contact. No customer profile is built from it. |
| read_draft_orders | Yes | To check what already exists before a retry and link an import record to the draft it produced, which is what makes creation duplicate-safe. |
| write_draft_orders | Yes | The single write the app performs: one draft order after a person confirms the reviewed lines. |
| write_products | No | Would allow edits to products, variants, prices and inventory. The catalog is read-only here: a price column from a customer file is shown, never applied. |
| write_customers | No | Would allow changes to customer records. The app only needs to identify an existing purchasing contact. |
| write_companies | No | Would allow changes to B2B companies, locations and contacts. Your company structure stays your own configuration in Shopify. |
| write_orders | No | Would allow changes to real orders. Kaupvik creates drafts and hands taxes, shipping, payment terms and the order itself back to your team in Shopify. |
That is the whole list. No order read scope, no payment scope and no theme, storefront or marketing scope is requested. If a future version needed more access, this page would state it before that version shipped.
Retention and deletion
What is stored, for how long, and how it is removed.
What is stored
- An import record for each list the team works through: operator, company location, line count, outcome and a link to the Shopify object it produced.
- The reviewed lines needed to reproduce a draft order and answer a question about it later. The original SKU text stays visible, so a person can always see what was asked for.
- Nothing beyond what the workflow and troubleshooting require. No production merchant data is held today, because the app is not launched.
Shopify's mandatory webhooks
Shopify requires every app to handle two privacy webhooks, and both are implemented in Kaupvik Quick Order:
- Customer data request. When a merchant receives a customer data request, Shopify notifies the app, which answers with what it holds for that customer.
- Shop deletion. When the app is removed from a store, Shopify notifies the app so the stored store data can be erased.
Requesting deletion by email
A merchant can also ask directly. Write to support@kaupvik.com with the store domain and what should be removed, and it is deleted. The privacy notice covers the same requests for merchant customer data.
Environment separation
Development and production never share anything.
- Separate Shopify apps. Development installs its own development app on a development store; production runs a separate app with its own credentials.
- Separate deployments. Each environment has its own web and API deployment, so a change reaches one and not the other.
- Separate databases. Each environment has its own PostgreSQL database, and live store data is not copied into development.
Hosting and database services are described in the privacy notice. No production merchant data is processed today, because the app is pre-release.
Reporting a concern
How to report a security concern.
Email hello@kaupvik.com with the subject "Security". There is no security@ alias, and no bug bounty programme or reward is offered. What helps most in a first message:
- What you observed, and what you expected instead.
- The store domain or environment involved.
- Steps to reproduce it, if you have them.
- When it happened, so logs can be checked.
Limits
What Kaupvik does not claim.
- No certification is claimed. Kaupvik holds and claims no SOC 2, ISO 27001 or PCI DSS certification.
- Standard transport security only. Data is protected in transit with TLS between your browser or Shopify and the app. No stronger encryption claim is made.
- No uptime commitment. No availability level is published for a pre-release app.
- Pre-release. The app is not launched, no public Shopify App Store listing exists yet, and no production merchant data is processed today.
- Maintained as it changes. This page is the current state and will be updated before the App Store listing opens.
Questions merchants ask
Data, boundaries and availability.
What data does Quick Order read?
Products and variants, companies and locations, and the minimum customer fields needed to choose a purchasing contact. It requests draft order write access and does not request write access to products, customers, companies or orders.
The security page lists the access scopes and the retention approach in plain language.
Who decides the price a buyer sees?
Shopify does. Kaupvik asks Shopify for eligibility and price in the context of the selected company location and displays the result. It does not run its own pricing engine and does not override catalog rules.
Does Kaupvik replace the Shopify admin experience?
No. The app runs inside Shopify Admin with Shopify's own components and respects Shopify staff permissions. Kaupvik does not imitate Shopify's interface, and Shopify remains the system of record for catalog, pricing, customers, orders and payment.
Is Kaupvik Quick Order available in the Shopify App Store?
Not yet. The app is pre-release: the merchant team workflow is built and demonstrable in a development store, and this site invites merchants to contact Kaupvik about early access.
Next step
Security questions are welcome before you install.
Pre-release: the App Store destination is reserved, but the listing is not public yet. The link may be unavailable until Shopify publishes it.