Security
Least privilege, encrypted in transit, deleted on uninstall.
How we intend to run Buyerframe and this website. Details will tighten as the app approaches App Store review.
Access
Buyerframe requests only the Shopify scopes it needs to build frames and render embeds. Staff access to production systems is limited, logged, and uses unique credentials plus second factor.
Transport and storage
Traffic to this site and the app uses HTTPS. Secrets live in the host environment (for example Vercel environment variables), not in the git repository. Shop data is stored in a region we will disclose to merchants before launch if it is not the United States.
Application
We keep dependencies current, review OAuth and webhook paths, and verify Shopify webhook signatures. Contact forms are validated on the server. We do not log full customer payloads to third-party debug tools.
Incidents
If we confirm a breach that affects merchant or customer data we will notify affected merchants and, where required, regulators, without unreasonable delay.
Report a concern
Email privacy@freerangeapps.com with “Security” in the subject. Please do not include secrets in the first message; we will open a safer channel.