Security

Protection without theatre.

AppMexa uses layered controls to protect merchant configuration, credentials and the operational systems behind our apps.

Encrypted transport

TLS protects data in transit. Sensitive application credentials are encrypted before storage where the product requires them.

Least privilege

Apps request only the Shopify access they need. Administrative access is restricted, authenticated and logged.

Operational visibility

Health checks, grouped errors and release context help us find faults without collecting unnecessary customer data.

Infrastructure

Production services run in isolated containers behind a managed TLS proxy and network firewall. Databases are not exposed publicly, backups are restricted, and operating-system security updates are automated.

Data handling

We minimise stored data, hash identifiers used for diagnostics, redact known secrets from error reports and enforce retention limits. Pixel and Conversions API credentials are never exposed in public telemetry.

Responsible disclosure

If you believe you have found a vulnerability, email support@appmexa.com with “Security report” in the subject. Please avoid accessing other people's data or disrupting production. We will acknowledge a valid report and work with you on a safe resolution.

Shared responsibility

Merchants should protect their Shopify accounts with strong authentication, limit staff permissions, obtain any legally required consent and rotate Meta credentials when staff access changes.