Security · Access · Deletion

Security and data handling, stated plainly.

Kaupvik Quick Order reads a short, named list of things from your Shopify store, asks Shopify to calculate prices, and writes exactly one draft order.
Pre-release

How does Kaupvik Quick Order handle security?

It reads products, B2B company context and the minimum customer fields needed to pick a purchasing contact, then creates a Shopify draft order once a person confirms the reviewed lines. It does not request write access to products, customers, companies or orders. Development and production run as separate apps, deployments and databases, and no production merchant data is processed today because the app is not launched.

The model in one screen

Read little, let Shopify decide, write one thing.

The security position is the shape of the app rather than a promise about intentions: a narrow read, no pricing engine of its own, one explicit write, and a person in front of every change.
  • Read what the task needs

    Products and variants, companies and locations, and the minimum customer fields needed to choose a purchasing contact. Nothing else is requested.

  • Let Shopify decide

    Prices and availability are computed by Shopify for the selected company location. Kaupvik has no pricing engine and does not override catalog rules.

  • Write one thing, after a person confirms

    Every write follows an explicit confirmation in the review workspace, and the result is a draft order your team continues in Shopify.

Data is limited to what the workflow and troubleshooting require. The app does not collect storefront browsing data, does not process payment details, and does not sell or share merchant data.

Access scopes

The exact Shopify access the app requests, and the access it refuses.

These are the scope strings declared in the app configuration. The development app and the production app declare the same list.
Shopify access scopes Kaupvik Quick Order requests, and the four it deliberately does not request. Each line says what the scope reaches and why that access is, or is not, needed.
ScopeRequestedWhat it reaches, and why
read_productsYesProducts and variants, so each line of a list matches a real variant and candidates can be offered when nothing matches exactly.
read_companiesYesCompanies, company locations and purchasing contacts, so a list is reviewed in the buying context you select.
read_customersYesOnly the minimum customer fields needed to select a purchasing contact. No customer profile is built from it.
read_draft_ordersYesTo check what already exists before a retry and link an import record to the draft it produced, which is what makes creation duplicate-safe.
write_draft_ordersYesThe single write the app performs: one draft order after a person confirms the reviewed lines.
write_productsNoWould allow edits to products, variants, prices and inventory. The catalog is read-only here: a price column from a customer file is shown, never applied.
write_customersNoWould allow changes to customer records. The app only needs to identify an existing purchasing contact.
write_companiesNoWould allow changes to B2B companies, locations and contacts. Your company structure stays your own configuration in Shopify.
write_ordersNoWould allow changes to real orders. Kaupvik creates drafts and hands taxes, shipping, payment terms and the order itself back to your team in Shopify.

That is the whole list. No order read scope, no payment scope and no theme, storefront or marketing scope is requested. If a future version needed more access, this page would state it before that version shipped.

Retention and deletion

What is stored, for how long, and how it is removed.

What is stored

  • An import record for each list the team works through: operator, company location, line count, outcome and a link to the Shopify object it produced.
  • The reviewed lines needed to reproduce a draft order and answer a question about it later. The original SKU text stays visible, so a person can always see what was asked for.
  • Nothing beyond what the workflow and troubleshooting require. No production merchant data is held today, because the app is not launched.

Shopify's mandatory webhooks

Shopify requires every app to handle two privacy webhooks, and both are implemented in Kaupvik Quick Order:

  • Customer data request. When a merchant receives a customer data request, Shopify notifies the app, which answers with what it holds for that customer.
  • Shop deletion. When the app is removed from a store, Shopify notifies the app so the stored store data can be erased.

Requesting deletion by email

A merchant can also ask directly. Write to support@kaupvik.com with the store domain and what should be removed, and it is deleted. The privacy notice covers the same requests for merchant customer data.

Environment separation

Development and production never share anything.

Test work and live work are kept apart by construction rather than by discipline.
  • Separate Shopify apps. Development installs its own development app on a development store; production runs a separate app with its own credentials.
  • Separate deployments. Each environment has its own web and API deployment, so a change reaches one and not the other.
  • Separate databases. Each environment has its own PostgreSQL database, and live store data is not copied into development.

Hosting and database services are described in the privacy notice. No production merchant data is processed today, because the app is pre-release.

Reporting a concern

How to report a security concern.

There is no separate security mailbox. A security report goes to the general address with a clear subject line, and is read by the people who build the product.

Email hello@kaupvik.com with the subject "Security". There is no security@ alias, and no bug bounty programme or reward is offered. What helps most in a first message:

  • What you observed, and what you expected instead.
  • The store domain or environment involved.
  • Steps to reproduce it, if you have them.
  • When it happened, so logs can be checked.

Limits

What Kaupvik does not claim.

  • No certification is claimed. Kaupvik holds and claims no SOC 2, ISO 27001 or PCI DSS certification.
  • Standard transport security only. Data is protected in transit with TLS between your browser or Shopify and the app. No stronger encryption claim is made.
  • No uptime commitment. No availability level is published for a pre-release app.
  • Pre-release. The app is not launched, no public Shopify App Store listing exists yet, and no production merchant data is processed today.
  • Maintained as it changes. This page is the current state and will be updated before the App Store listing opens.

Questions merchants ask

Data, boundaries and availability.

What data does Quick Order read?

Products and variants, companies and locations, and the minimum customer fields needed to choose a purchasing contact. It requests draft order write access and does not request write access to products, customers, companies or orders.

The security page lists the access scopes and the retention approach in plain language.

Who decides the price a buyer sees?

Shopify does. Kaupvik asks Shopify for eligibility and price in the context of the selected company location and displays the result. It does not run its own pricing engine and does not override catalog rules.

Does Kaupvik replace the Shopify admin experience?

No. The app runs inside Shopify Admin with Shopify's own components and respects Shopify staff permissions. Kaupvik does not imitate Shopify's interface, and Shopify remains the system of record for catalog, pricing, customers, orders and payment.

Is Kaupvik Quick Order available in the Shopify App Store?

Not yet. The app is pre-release: the merchant team workflow is built and demonstrable in a development store, and this site invites merchants to contact Kaupvik about early access.

Next step

Security questions are welcome before you install.

If you need a specific answer about data handling for your store, ask before installing rather than after. Reports go to the general mailbox with the subject "Security".
Pre-release app. No certification is claimed, no uptime level is promised, and no production merchant data is processed today.
View on Shopify App StoreRead the privacy notice

Pre-release: the App Store destination is reserved, but the listing is not public yet. The link may be unavailable until Shopify publishes it.