Home / security

Security Policy

Access model

We never ask for your Shopify login or password. You create a revocable Admin API token per store, scoped read-only on the source. You can revoke either token at any moment, and we ask you to revoke both at handover.

Encryption

Tokens are encrypted at rest with AES-256-GCM; decryption requires a key held only in the runtime environment, never in the database. All traffic is TLS. Payment data never touches our systems — checkout is entirely Stripe-hosted.

Infrastructure

The service runs on Cloudflare's network with the database and application in the same trust boundary; admin access is password-protected and credential reveals are deliberate, logged actions.

During migration

Your source store is accessed read-only. Working exports are retained only for the re-migration window of your package, then deleted.

What we never ask for, and never do

We never request your Shopify account password, and we never ask to be added as a staff user with login access. Migration runs on Admin API tokens from a custom app you create and can revoke in one click, scoped to exactly the permissions the job needs. Credentials sent by email or chat are not accepted as delivered — they go through the encrypted customer area or they do not reach us.

Your existing store is only ever read from. Every write goes to the destination store, so nothing about the store you still depend on can be made worse by a migration in progress. No step in the process deletes, edits or republishes anything on the source.

Tokens are decrypted only in the runtime that needs them — never in the database, never in a log line. Migration containers are single-use: one job, one VM, destroyed when the job ends.

Disclosure

Found a vulnerability? [email protected] — we respond within one business day.

Operator

This service is operated by Shopify2Shopify, Unit 122153, PO Box 6945, London, W1A 6US.