POS Notices and Alerts POS Notices and Alerts

Security Practices — POS Notices and Alerts

Effective date: August 5, 2026

Staff access and password requirements

Security incident response policy

If we discover or are notified of a security incident — a compromised account, a leaked API credential, or unauthorized access to a merchant's data:

  1. Contain. Revoke or rotate the affected credential(s) immediately.
  2. Assess. Determine what data, if any, could have been exposed, and for how long. Given this app's architecture, most protected customer data is never persisted outside Shopify's own systems, which limits what a compromise of dinkbit's own infrastructure could actually expose.
  3. Notify. Notify affected merchants, and Shopify (via Partner Dashboard support), within 72 hours of confirming an incident involving personal data — describing what happened and what we're doing about it. Notify any affected end customers as required by applicable law.
  4. Remediate. Fix the root cause before considering the incident closed.
  5. Document. Record what happened, the timeline, and the fix, for future reference and for evidence if Shopify requests it.

Contact

Report a suspected security issue to [email protected].