Security & Data Handling
Your merchants trusted you; you're trusting us. This page lists exactly what Crust stores, what it never touches, and how it's protected — specific enough that you (or the AI assistant reviewing our snippets) can verify the claims against what the product actually does.
1. What we store, per workspace
Each workspace holds four kinds of data, all keyed to that workspace alone:
- App lifecycle & billing events from the Shopify Partner API — installs, uninstalls, subscription charges, payouts. The Partner API contains no merchant contact details.
- Merchant business contact records — shop domain, business email, owner name, country, Shopify plan, and (only if you opt in) phone. These arrive via your tracking pixel, your backfill route, or a CSV you import.
- In-app usage events — page path, session id, and timestamp from the tracking pixel. No form contents, no keystrokes, no screen recording.
- App users — the name, email, and role of Shopify staff who open your app, captured only from cryptographically verified session tokens.
2. What we never store
- Merchant store access tokens. When the pixel verifies a session token, the OAuth token-exchange result lives only for the duration of that single request — it is used to read the shop's business contact card and then discarded. It is never written to disk or database.
- Buyer / end-customer data. Crust never calls Shopify's Orders, Customers, or any Protected Customer Data API. Your merchants' shoppers are invisible to us, by design.
- Card numbers. Billing runs through Stripe; card data never touches our servers.
3. How it's protected
- Secrets encrypted at rest. Your Shopify client secret and Partner API token are encrypted with AES-256-GCM before storage and decrypted only in memory at the moment of use.
- Contact records require cryptographic proof. Analytics events are accepted on your pixel token, but a contact record is written only after the merchant's session token is verified (HMAC-SHA256) against your client secret. Spoofed pixel traffic can pollute a page-view count; it can never write to your contact book.
- Workspace isolation. Every row is keyed to your workspace. Your API key reads your workspace only. We do not aggregate, share, enrich, or sell data across customers — your merchant list is yours, full stop.
- Account security. Passwords are scrypt-hashed, sessions are httpOnly cookies, and your API key can be rotated instantly from the Integration page.
- Transport. All traffic — dashboard, pixel, and API — is TLS-encrypted.
4. Deletion & data return
One API call erases a merchant's contact record, app users, and usage events from your workspace. Wire it wherever your retention policy says a merchant's data should go — for example inside your shop/redact webhook handler when you receive an erasure request:
await fetch("https://heycrust.com/api/identify", {
method: "DELETE",
headers: {
"Content-Type": "application/json",
Authorization: "Bearer " + process.env.CRUST_API_KEY,
},
body: JSON.stringify({ myshopifyDomain: payload.shop_domain }),
});A retention-policy note before you automate this: Shopify fires shop/redact automatically about 48 hours after every uninstall — not only on explicit erasure requests. Forwarding it unconditionally erases exactly the churned merchants you may want to win back. Many developers retain business contact records under legitimate interest and honor explicit erasure requests individually; others prefer strict auto-deletion. Decide with your counsel — Crust deletes whenever you say so, immediately.
You can export your customers and events as CSV at any time from the dashboard, and request full workspace deletion at hello@heycrust.com; we complete it within 30 days.
5. What we don't claim
We are a small team. We do not yet hold a SOC 2 report or ISO certification, and we won't pretend otherwise with borrowed badges. What we offer instead is precision: this page describes exactly what the product does, it is written to be checked against our actual behavior, and our Data Processing Agreement makes it contractual. Found something that looks wrong? Tell us at hello@heycrust.com — security reports get same-day attention.