Security & Incident Response Policy

Last updated: July 20, 2026

This policy describes how Promptly protects personal data and responds to security incidents. It supplements our Privacy Policy and Data Processing Agreement.

1. Data protection measures

2. Access control & least privilege

Access to systems holding personal data is restricted to the app operator on a least-privilege basis. There is no routine human access to customer personal data; the data is processed programmatically to deliver the app's functionality.

3. Access logging

Promptly maintains an auditable log of every access to, disclosure of, and erasure of personal data. The following events are recorded with a timestamp, the shop, the action, and the processing purpose:

The access log itself contains no raw personal data — email/phone subjects are stored as a salted one-way hash (or a Shopify resource identifier), so the log is auditable without becoming a store of personal data. Infrastructure-level access logs are additionally provided by our hosting sub-processors (Cloudflare, Neon).

4. Data loss prevention

Personal data is held in a managed PostgreSQL service with automated, encrypted backups and point-in-time recovery. Least-privilege access, credential encryption, and environment separation reduce the risk of loss or unauthorised exfiltration.

5. Incident response

If we become aware of a security incident affecting personal data, we follow this process:

  1. Detect & triage — assess scope, severity, and whether personal data is affected.
  2. Contain — revoke/rotate affected credentials, isolate affected systems, and stop ongoing exposure.
  3. Eradicate & recover — remove the cause and restore service from a known-good state.
  4. Notify — notify affected Merchants without undue delay (and, where we are the processor, provide the information they need to meet their own regulatory notification obligations, e.g. GDPR's 72-hour timeline). Notify Shopify and regulators where required.
  5. Review — conduct a post-incident review and implement corrective actions.

6. Sub-processor security

Our infrastructure sub-processors maintain their own security programs and certifications, including Cloudflare (SOC 2 Type II, ISO 27001) and Neon (SOC 2 Type II). We rely on Shopify's platform security for data exchanged through the Shopify Admin API.

7. Reporting a vulnerability

To report a security concern or suspected incident, contact support@promptlyapp.co. We aim to acknowledge reports promptly and will keep you informed of remediation.