Security Practices — POS Notices and Alerts
Effective date: August 5, 2026
Staff access and password requirements
- Every account that can reach protected customer data, or systems that can reach it, requires a strong, unique password stored in a password manager and never reused across services.
- Two-factor authentication is enabled wherever it's supported.
- Access is limited to the people who actually need it for this project.
Security incident response policy
If we discover or are notified of a security incident — a compromised account, a leaked API credential, or unauthorized access to a merchant's data:
- Contain. Revoke or rotate the affected credential(s) immediately.
- Assess. Determine what data, if any, could have been exposed, and for how long. Given this app's architecture, most protected customer data is never persisted outside Shopify's own systems, which limits what a compromise of dinkbit's own infrastructure could actually expose.
- Notify. Notify affected merchants, and Shopify (via Partner Dashboard support), within 72 hours of confirming an incident involving personal data — describing what happened and what we're doing about it. Notify any affected end customers as required by applicable law.
- Remediate. Fix the root cause before considering the incident closed.
- Document. Record what happened, the timeline, and the fix, for future reference and for evidence if Shopify requests it.
Contact
Report a suspected security issue to [email protected].