Security & Incident Response Policy
Last updated: July 20, 2026
This policy describes how Promptly protects personal data and responds to security incidents. It supplements our Privacy Policy and Data Processing Agreement.
1. Data protection measures
- Encryption in transit: All connections use TLS/HTTPS.
- Encryption at rest: The database (Neon PostgreSQL) is encrypted at rest, and managed backups are encrypted. Stored third-party credentials (marketing-platform API keys) and subscriber contact details (email addresses and phone numbers) are additionally encrypted with AES-256-GCM at the application layer.
- Data minimisation: We store only the email, phone, name (when a popup collects it), and popup responses a visitor submits, plus anonymous visitor identifiers and visit context. We do not process customer addresses or payment data.
- Environment separation: Test/staging and production run in separate environments with separate databases.
- Authentication: Merchant access is via Shopify OAuth; operator access to infrastructure requires multi-factor authentication and strong, unique passwords.
2. Access control & least privilege
Access to systems holding personal data is restricted to the app operator on a least-privilege basis. There is no routine human access to customer personal data; the data is processed programmatically to deliver the app's functionality.
3. Access logging
Promptly maintains an auditable log of every access to, disclosure of, and erasure of personal data. The following events are recorded with a timestamp, the shop, the action, and the processing purpose:
- Creating or updating a Shopify customer record from a signup;
- Setting or updating email/SMS marketing consent;
- Disclosing a contact to the Merchant's connected marketing platform;
- Exporting personal data in response to a data-subject request;
- Erasing personal data (individual or shop-level).
The access log itself contains no raw personal data — email/phone subjects are stored as a salted one-way hash (or a Shopify resource identifier), so the log is auditable without becoming a store of personal data. Infrastructure-level access logs are additionally provided by our hosting sub-processors (Cloudflare, Neon).
4. Data loss prevention
Personal data is held in a managed PostgreSQL service with automated, encrypted backups and point-in-time recovery. Least-privilege access, credential encryption, and environment separation reduce the risk of loss or unauthorised exfiltration.
5. Incident response
If we become aware of a security incident affecting personal data, we follow this process:
- Detect & triage — assess scope, severity, and whether personal data is affected.
- Contain — revoke/rotate affected credentials, isolate affected systems, and stop ongoing exposure.
- Eradicate & recover — remove the cause and restore service from a known-good state.
- Notify — notify affected Merchants without undue delay (and, where we are the processor, provide the information they need to meet their own regulatory notification obligations, e.g. GDPR's 72-hour timeline). Notify Shopify and regulators where required.
- Review — conduct a post-incident review and implement corrective actions.
6. Sub-processor security
Our infrastructure sub-processors maintain their own security programs and certifications, including Cloudflare (SOC 2 Type II, ISO 27001) and Neon (SOC 2 Type II). We rely on Shopify's platform security for data exchanged through the Shopify Admin API.
7. Reporting a vulnerability
To report a security concern or suspected incident, contact support@promptlyapp.co. We aim to acknowledge reports promptly and will keep you informed of remediation.