Security policy

Last updated October 1, 2026

This policy describes how Mint Labs protects the data Mint Bulk Editor handles. The app works only with merchants' own product data — it has no access to orders or customer data. It applies to everyone at Mint Labs with access to our systems.

Data loss prevention

  • We keep as little data as possible: the jobs a merchant sets up and, per field a job changes, IDs, titles and the values before and after. The app never requests customer data.
  • The value before each change is read from Shopify and recorded before the app writes anything, so every job can be undone; the per-change record can be downloaded by the merchant as a CSV.
  • Our database is Cloudflare D1: encrypted at rest, with point-in-time recovery so it can be restored to any minute in the retention window. Files are stored in Cloudflare R2, encrypted at rest.
  • Export files are downloaded only through signed links that are valid for one file, one store and 30 minutes; files are deleted after 7 days.
  • All traffic uses HTTPS (TLS). Production and development use separate databases; development uses fictional sample data only.
  • Webhooks are verified with Shopify HMAC signatures and admin requests with Shopify session tokens; unsigned or invalid requests are rejected. Background jobs run only from the app's own queue and scheduler and are not reachable from the internet.

Access control

  • Only authorised Mint Labs personnel who need it to run and support the app can access production systems.
  • The app has no internal screen that lets us browse stores' data.
  • Access is removed immediately when it is no longer needed.

Passwords and authentication

  • Every account with access to production (hosting and Shopify Partner) uses a strong, unique password stored in a password manager.
  • Two-factor authentication is required on all of those accounts.
  • API secrets are stored as encrypted environment secrets, never in source code, and are rotated after any suspected exposure.

Logging

  • Every request to the app is logged with a timestamp by our hosting provider's request logs. Our own log lines contain job IDs and outcomes, never personal data.
  • Every change the app makes is recorded per field and in the job's activity log, visible to the merchant.
  • Logs are reviewed when investigating errors or suspected incidents.

Security incident response

  1. Report. Anyone can report a suspected issue to support@stickermint.com. We acknowledge reports within one business day.
  2. Contain. We stop the exposure first: disable the affected feature, revoke and rotate keys and access tokens, and block abusive traffic.
  3. Investigate. We use request logs, the per-change records and database history to find what happened, which shops and data were affected, and when.
  4. Notify. We notify affected merchants without undue delay and within 72 hours of confirming an incident, and tell Shopify where required, with what happened and what we are doing about it.
  5. Recover. We fix the root cause and, if needed, restore data from point-in-time recovery and help merchants restore values from the recorded before-values.
  6. Review. We record each incident and the lessons learned, and update this policy.

Contact

Mint Labs — support@stickermint.com