Security policy

Last updated September 29, 2026

This policy describes how Mint Labs protects the data Mint Back in Stock handles, including personal data of merchants' customers processed on behalf of merchants. It applies to everyone at Mint Labs with access to our systems.

Data loss prevention

  • We keep as little data as possible. For each alert request we store the shopper's email address, the variant, the date and whether they ticked the optional marketing box — nothing else — and delete the request as soon as its alert is sent (or after 180 days).
  • Email addresses are encrypted by the app (AES-256-GCM) before they are written to the database, with a key stored as a separate encrypted secret. Lookups, duplicates and unsubscribes use a keyed one-way hash, so the address itself is only decrypted to send the alert or to show it to the merchant.
  • Requests are never dropped on errors: a request moves to "sent" only after the email service accepted the message; anything else puts it back in line, and stuck messages are recovered automatically.
  • Our database is Cloudflare D1: encrypted at rest, with point-in-time recovery so it can be restored to any minute in the retention window.
  • All traffic uses HTTPS (TLS). Production and development use separate databases; development never uses real merchant or shopper data.
  • Webhooks and storefront requests are verified with Shopify HMAC signatures; unsigned requests are rejected. Unsubscribe links are signed.

Access control

  • Only authorised Mint Labs personnel who need it to run and support the app can access production systems.
  • The app has no internal screen that lets us browse customers' personal data.
  • Access is removed immediately when it is no longer needed.

Passwords and authentication

  • Every account with access to production (hosting and Shopify Partner) uses a strong, unique password stored in a password manager.
  • Two-factor authentication is required on all of those accounts.
  • API secrets are stored as encrypted environment secrets, never in source code, and are rotated after any suspected exposure.

Logging

  • Every request to the app, including requests that process personal data, is logged with a timestamp by our hosting provider's request logs. Logs never contain shoppers' email addresses, names or addresses.
  • Logs are reviewed when investigating errors or suspected incidents.

Security incident response

  1. Report. Anyone can report a suspected issue to support@stickermint.com. We acknowledge reports within one business day.
  2. Contain. We stop the exposure first: disable the affected feature, revoke and rotate keys and access tokens, and block abusive traffic.
  3. Investigate. We use request logs and database history to find what happened, which shops and data were affected, and when.
  4. Notify. If personal data was affected, we notify affected merchants without undue delay and within 72 hours of confirming the incident, and tell Shopify where required, with what happened and what we are doing about it.
  5. Recover. We fix the root cause and, if needed, restore data from point-in-time recovery.
  6. Review. We record each incident and the lessons learned, and update this policy.

Contact

Mint Labs — support@stickermint.com