Trust & Security

Trust is not a feature. It is the foundation.

ShopRise reads your catalogue, rewrites it, and publishes back to your storefront. That only works if you can see exactly what we touch, what we store, and what we will never ask for.

GDPR Compliant
EU Data residency
AES-256 At rest
TLS 1.3 In transit
Our posture

Four commitments, written
so you can hold us to them.

Nothing on this page is aspirational language. If a control is in progress, it says so.

Data protection

Your catalogue, your content and your rankings live in an EU-hosted database, isolated per store. We store what we need to score and improve your storefront, and nothing else. No customer PII, no orders, no payment data ever enters our systems.

Access control

Least privilege by default. Every engineer authenticates with SSO and MFA, production access is scoped and time-bound, and each write back to your store is logged with the person who approved it in the Change Queue.

Encryption

TLS 1.3 in transit and AES-256 at rest across the application database, backups and object storage. Shopify access tokens are encrypted with a separate key and are never written to logs or analytics.

AI data handling

We call model APIs under agreements that disable training on our inputs and outputs. We do not fine-tune models on customer content, and one merchant's catalogue never becomes another merchant's answer.

AI data handling

Your data is never
training data.

This is the fear every merchant has when they hand a catalogue to an AI tool: that the descriptions they spent years writing quietly end up inside a model that a competitor will use next quarter. So let us be exact about what happens.

ShopRise is a client of model providers, not a model builder. Your content travels to an inference endpoint, an answer comes back, and that is the end of the transaction. There is no fine-tuning step, no shared embedding pool, no "improve the product" checkbox that we quietly leave on.

Current status: zero-retention and no-training terms are in place with our primary model provider. Any provider we add is held to the same bar before it processes a single customer record.

01

We call APIs. We do not fine-tune.

Your product copy, brand context and rankings are sent as inference inputs. No customer content is used to train, fine-tune or evaluate a model, ours or anyone else's.

02

Training on API inputs is contractually disabled.

Our agreements with model providers exclude our inputs and outputs from model training. This is a contract term, not a setting we hope stays switched off.

03

Short retention windows.

Prompt and response logs are kept only long enough to debug a failed job, then deleted. Generated drafts live in your Change Queue, in your account, under your control.

04

No cross-customer mixing.

Every store is a separate tenant with its own row-level isolation. One merchant's catalogue is never used as context, as an example, or as inspiration for another merchant's output.

Permission model

How ShopRise connects
to your store.

One OAuth install, seven scopes, and a hard boundary around everything that has a person's name on it. This is the exact screen Shopify shows you before you click install.

admin.shopify.com / apps / shoprise / install OAuth 2.0
ShopRise would like to access your store Approve the scopes below to install. You can revoke them at any time by uninstalling the app.
Scopes requested
  • read_products

    Read titles, descriptions, variants and images so we can score them and research the right keywords.

  • write_products

    Publish the title, description and metafield changes you approved in the Change Queue. Never before you approve.

  • read_content

    Read your existing blog articles to audit them and detect gaps against your competitors.

  • write_content

    Publish approved articles and article metadata back to your blog.

  • read_themes

    Read your theme templates to find missing structured data and render-blocking scripts.

  • write_themes

    Install the theme app extension that injects schema. No other theme file is touched.

  • read_online_store_pages

    Read static pages such as About and FAQ so the AI understands your brand context.

We never request
  • read_customers

    Customer names, emails and addresses. We never see them.

  • read_orders

    Orders, carts and fulfilment. SEO does not need your revenue lines.

  • read_payment_*

    Payment methods, cards and payouts. Out of scope by design.

Customer PII, orders and payment data are outside our permission set entirely. Not redacted, not filtered: never requested, so never received.

Every write back to your store passes through the Change Queue and carries the name of the person who approved it.
Subprocessors

Everyone who touches your data.

The complete list. If a vendor is not on it, it does not process your data.

Subprocessor Purpose Region
Anthropic Claude API for content generation and semantic analysis US / EU
Vercel Application hosting and CDN EU + global edge
Supabase Application database and authentication EU
SEMrush Keyword volume and SERP data EU / US
Shopify Store integration via the Admin API Region of the merchant
Google Analytics 4 Traffic and conversion attribution EU / US
Resend Transactional email EU

This list is kept current and reviewed every quarter. Customers on an active plan are notified by email before a new subprocessor begins processing their data, and can object. Last reviewed: July 2026.

Compliance

What we have, and what
we do not have yet.

ShopRise is a young product. Plenty of vendors of our age claim badges they have not earned. Here is the unedited version.

GDPR

Compliant

We process personal data as a processor on your behalf, under a data processing agreement. Transfers outside the EU run on Standard Contractual Clauses. A DPA is available on request and is included by default on Enterprise.

SOC 2 Type II

Readiness in progress

Our controls are documented and being implemented against the SOC 2 Trust Services Criteria. We are not SOC 2 certified today, and we will not say we are until an auditor has signed the report. We will publish it here when it exists.

ISO 27001

Aligned, not certified

Our information security policies are written against the ISO 27001 Annex A control set. There is no certificate behind that alignment yet, so treat it as posture rather than proof.

Data subject rights

Supported

Access, rectification, erasure, restriction, portability and objection. Send a request to privacy@shoprise.ai and we respond within 30 days, or sooner if the request is straightforward.

Responsible disclosure

Found something?
Tell us first.

We would rather hear it from you than from a customer. Good-faith research is welcome and will never be met with a lawyer.

security@shoprise.ai
How to report
  • Email security@shoprise.ai with the affected URL or endpoint, reproduction steps, and the impact you believe it has.
  • We acknowledge every report within 2 business days, with a human reply, not an autoresponder.
  • Triage and a remediation timeline follow within 10 business days. You stay in the loop until it ships.
  • We credit researchers who want to be credited. We do not run a paid bounty programme today, and we will not imply that we do.
Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, we will not pursue or support legal action against you, and we will help make that clear to anyone who asks.

Good faith means: do not access, modify or destroy data that is not yours, do not degrade the service for other users, stop as soon as you have proof of a vulnerability, and give us a reasonable window to fix it before publishing.

Out of scope: volumetric denial of service, spam or social engineering of our staff, scanner output with no demonstrated impact, and missing best-practice headers that are not exploitable on their own.

Security FAQ

The questions your
CTO will ask.

Short answers, no hedging. If yours is not here, write to us and we will answer it in the same tone.

Do you train AI models on my product data?
No. ShopRise calls third-party model APIs, primarily Anthropic's Claude, under commercial agreements where training on our inputs and outputs is contractually disabled. We do not fine-tune, distil or otherwise build models on customer content, and no merchant's catalogue is used to produce answers for another merchant.
What Shopify permissions does ShopRise request?
Read and write access to products, content, themes and online store pages, which is the minimum needed to audit your storefront and publish approved changes. We do not request customer, order or payment scopes, so that data never reaches us. The full scope list is visible in your Shopify admin at any time, and you can revoke it by uninstalling the app.
Where is my data stored, and does it leave the EU?
The application database and backups are hosted in the EU. Some subprocessors, including our AI provider and SEMrush, may process data in the United States. Those transfers run on Standard Contractual Clauses and are listed in the subprocessor table on this page.
Are you SOC 2 or ISO 27001 certified?
Not yet, and we will not pretend otherwise. ShopRise is GDPR compliant today. SOC 2 Type II readiness is in progress and our policies are written against ISO 27001 Annex A controls, but neither audit has been completed. If your procurement team needs a security questionnaire filled in before that, email security@shoprise.ai and we will answer it honestly.
What happens to my data if I cancel?
Uninstalling the Shopify app immediately revokes our access token. Your account data, scan history and generated content are deleted within 30 days of cancellation, and backups roll off within 35 days. You can request an immediate deletion instead, and we will confirm it in writing.
Need a signed DPA, a security questionnaire or a penetration test summary? Ask security

See what we can read, before we read it.

Run the free scan first. It uses public data only, so you can judge the output before you install anything.

No install required · Report within 48 hours