Built to protect your data — and your clients'
Solcro handles store and behavior data for brands and agencies. Here's exactly how we keep it isolated, private, and secure.
Tenant isolation by default
Every record is locked to its owner with row-level security on all tables. One account can never read another account's stores, audits, reports, or data.
Server-enforced access
Plan limits and ownership are enforced in the database and edge functions — not just hidden in the UI. Locked features are protected technically, not visually.
Privacy-safe behavior tracking
Form inputs are masked, sensitive fields are never read, checkout and account pages are skipped, and no fingerprinting is used. We capture interaction patterns, not personal data.
Secrets stay server-side
Shopify access tokens and API keys live in an admin-only vault that is never selected client-side or exposed to the browser.
Encrypted in transit
All traffic between you, Solcro, and our providers is encrypted over HTTPS/TLS.
Your data is never sold
We never sell your account, store, or audit data — and we never share your store's customer data with anyone for advertising or any other purpose.
How we handle Shopify data
- Orders are read field-limited (totals, dates, financial status) and stored only as aggregates — never per-customer records.
- No customer personal data (names, emails, addresses) is stored, and none is ever sent to AI providers.
- Mandatory Shopify privacy webhooks (data request, customer redact, shop redact) are honored automatically.
- Uninstalling the app deactivates the store and deletes its vaulted access token.
Subprocessors
The trusted providers we use to deliver Solcro, and the data each one handles.
| Provider | Purpose |
|---|---|
| InsForge | Backend, database, authentication, hosting |
| Stripe | Subscription billing & payments |
| Anthropic | AI analysis for audits, rewrites, and objections |
| OpenRouter | AI fallback provider |
| Netlify | Frontend hosting & CDN |
| Google Analytics | Product analytics (consent-gated) |
| Advertising & conversion measurement (marketing site) | |
| lemlist | Visitor identification & outreach attribution (marketing site) |
| WordPress mShots | Storefront screenshots for audits |
Compliance
- GDPR-aligned data handling, with a Data Processing Agreement available.
- A cookie banner controls analytics cookies — Google Analytics honors your choice via Consent Mode. We also run always-on marketing technologies that are not gated by the banner — a Reddit advertising pixel and lemlist visitor tracking (which may identify visitors who arrive from our outreach campaigns) — for campaign measurement and attribution; these never carry store or customer data.
- Shopify Protected Customer Data posture: aggregate-only, no PII.
- Have specific requirements (custom DPA, security review)? Contact us.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email security@solcro.com and we'll respond promptly. Please give us reasonable time to remediate before public disclosure.
Questions about security or data handling?
We're happy to walk your team or your clients through how Solcro protects data.
Talk to us