Security policy
Last updated September 30, 2026
This policy describes how Mint Labs protects the data Mint Forms handles, including shoppers' personal data processed on behalf of merchants. It applies to everyone at Mint Labs with access to our systems.
Data loss prevention
- We keep as little as possible, for as short as possible: submissions are deleted automatically after the merchant's retention period, files that were uploaded but never sent are deleted after 2 hours, and IP addresses are never stored (only short-lived keyed hashes for rate limits).
- Submissions live in Cloudflare D1 (encrypted at rest, with point-in-time recovery). Uploaded files live in a private Cloudflare R2 bucket (encrypted at rest) under random keys; there is no public URL for any file.
- A submission is saved before any notification email is sent, so an email outage never loses it. Failed emails are shown to the merchant and retried.
- All traffic uses HTTPS (TLS). Production and development use separate databases; development never uses real merchant or shopper data.
- Storefront submissions arrive only through Shopify's app proxy and are verified with Shopify's HMAC signature; webhooks are verified the same way; unsigned requests are rejected. Every answer is validated on the server against the merchant's saved form, and uploaded files are checked by their content (images and PDF only).
Access control
- Only authorised Mint Labs personnel who need it to run and support the app can access production systems.
- Submissions and files are shown only inside the merchant's authenticated Shopify admin (session tokens, checked on every request). The app has no screen that lets us browse shoppers' submissions.
- Access is removed immediately when it is no longer needed.
Passwords and authentication
- Every account with access to production (hosting, Shopify Partner and email) uses a strong, unique password stored in a password manager.
- Two-factor authentication is required on all of those accounts.
- API secrets are stored as encrypted environment secrets, never in source code, and are rotated after any suspected exposure.
Logging
- Every request to the app, including requests that process personal data, is logged with a timestamp by our hosting provider's request logs. Logs never contain what shoppers typed, their email addresses, IP-derived keys or file contents.
- Logs are reviewed when investigating errors or suspected incidents.
Security incident response
- Report. Anyone can report a suspected issue to support@stickermint.com. We acknowledge reports within one business day.
- Contain. We stop the exposure first: disable the affected feature, revoke and rotate keys and access tokens, and block abusive traffic.
- Investigate. We use request logs and database history to find what happened, which shops and data were affected, and when.
- Notify. If personal data was affected, we notify affected merchants without undue delay and within 72 hours of confirming the incident, and tell Shopify where required, with what happened and what we are doing about it.
- Recover. We fix the root cause and, if needed, restore data from point-in-time recovery.
- Review. We record each incident and the lessons learned, and update this policy.
Contact
Mint Labs — support@stickermint.com