Skip to content
Security & data protection

Built to protect your data — and your clients'

Solcro handles store and behavior data for brands and agencies. Here's exactly how we keep it isolated, private, and secure.

Tenant isolation by default

Every record is locked to its owner with row-level security on all tables. One account can never read another account's stores, audits, reports, or data.

Server-enforced access

Plan limits and ownership are enforced in the database and edge functions — not just hidden in the UI. Locked features are protected technically, not visually.

Privacy-safe behavior tracking

Form inputs are masked, sensitive fields are never read, checkout and account pages are skipped, and no fingerprinting is used. We capture interaction patterns, not personal data.

Secrets stay server-side

Shopify access tokens and API keys live in an admin-only vault that is never selected client-side or exposed to the browser.

Encrypted in transit

All traffic between you, Solcro, and our providers is encrypted over HTTPS/TLS.

Your data is never sold

We never sell your account, store, or audit data — and we never share your store's customer data with anyone for advertising or any other purpose.

How we handle Shopify data

  • Orders are read field-limited (totals, dates, financial status) and stored only as aggregates — never per-customer records.
  • No customer personal data (names, emails, addresses) is stored, and none is ever sent to AI providers.
  • Mandatory Shopify privacy webhooks (data request, customer redact, shop redact) are honored automatically.
  • Uninstalling the app deactivates the store and deletes its vaulted access token.

Subprocessors

The trusted providers we use to deliver Solcro, and the data each one handles.

ProviderPurpose
InsForgeBackend, database, authentication, hosting
StripeSubscription billing & payments
AnthropicAI analysis for audits, rewrites, and objections
OpenRouterAI fallback provider
NetlifyFrontend hosting & CDN
Google AnalyticsProduct analytics (consent-gated)
RedditAdvertising & conversion measurement (marketing site)
lemlistVisitor identification & outreach attribution (marketing site)
WordPress mShotsStorefront screenshots for audits

Compliance

  • GDPR-aligned data handling, with a Data Processing Agreement available.
  • A cookie banner controls analytics cookies — Google Analytics honors your choice via Consent Mode. We also run always-on marketing technologies that are not gated by the banner — a Reddit advertising pixel and lemlist visitor tracking (which may identify visitors who arrive from our outreach campaigns) — for campaign measurement and attribution; these never carry store or customer data.
  • Shopify Protected Customer Data posture: aggregate-only, no PII.
  • Have specific requirements (custom DPA, security review)? Contact us.

Responsible disclosure

Found a vulnerability? We want to hear from you. Email security@solcro.com and we'll respond promptly. Please give us reasonable time to remediate before public disclosure.

Questions about security or data handling?

We're happy to walk your team or your clients through how Solcro protects data.

Talk to us