Security policy
Last updated October 1, 2026
This policy describes how Mint Labs protects the data Mint Bulk Editor handles. The app works only with merchants' own product data — it has no access to orders or customer data. It applies to everyone at Mint Labs with access to our systems.
Data loss prevention
- We keep as little data as possible: the jobs a merchant sets up and, per field a job changes, IDs, titles and the values before and after. The app never requests customer data.
- The value before each change is read from Shopify and recorded before the app writes anything, so every job can be undone; the per-change record can be downloaded by the merchant as a CSV.
- Our database is Cloudflare D1: encrypted at rest, with point-in-time recovery so it can be restored to any minute in the retention window. Files are stored in Cloudflare R2, encrypted at rest.
- Export files are downloaded only through signed links that are valid for one file, one store and 30 minutes; files are deleted after 7 days.
- All traffic uses HTTPS (TLS). Production and development use separate databases; development uses fictional sample data only.
- Webhooks are verified with Shopify HMAC signatures and admin requests with Shopify session tokens; unsigned or invalid requests are rejected. Background jobs run only from the app's own queue and scheduler and are not reachable from the internet.
Access control
- Only authorised Mint Labs personnel who need it to run and support the app can access production systems.
- The app has no internal screen that lets us browse stores' data.
- Access is removed immediately when it is no longer needed.
Passwords and authentication
- Every account with access to production (hosting and Shopify Partner) uses a strong, unique password stored in a password manager.
- Two-factor authentication is required on all of those accounts.
- API secrets are stored as encrypted environment secrets, never in source code, and are rotated after any suspected exposure.
Logging
- Every request to the app is logged with a timestamp by our hosting provider's request logs. Our own log lines contain job IDs and outcomes, never personal data.
- Every change the app makes is recorded per field and in the job's activity log, visible to the merchant.
- Logs are reviewed when investigating errors or suspected incidents.
Security incident response
- Report. Anyone can report a suspected issue to support@stickermint.com. We acknowledge reports within one business day.
- Contain. We stop the exposure first: disable the affected feature, revoke and rotate keys and access tokens, and block abusive traffic.
- Investigate. We use request logs, the per-change records and database history to find what happened, which shops and data were affected, and when.
- Notify. We notify affected merchants without undue delay and within 72 hours of confirming an incident, and tell Shopify where required, with what happened and what we are doing about it.
- Recover. We fix the root cause and, if needed, restore data from point-in-time recovery and help merchants restore values from the recorded before-values.
- Review. We record each incident and the lessons learned, and update this policy.
Contact
Mint Labs — support@stickermint.com