Security at Curobi
Curobi is built so there is as little of your data to protect as possible. It runs on Shopify’s native subscription and billing rails, and it persists only Shopify identifiers and subscription status — not raw customer data. This page explains how the app is secured and what happens if something goes wrong.
The core principle: data minimization. Curobi never handles, sees, or stores payment-card data — recurring charges are processed by Shopify. Customer names and addresses are read only in-request to create a subscription contract and arenever written to our database. What we store at rest is limited to Shopify identifiers (GIDs) and subscription status.
1. Built on Shopify’s native rails
Every recurring charge runs on Shopify Subscription Contracts and Shopify’s own checkout. There is no third-party billing processor and no payment redirect, so Curobi is never in the path of card data. Because subscription orders live in Shopify like any other order, your existing security, fulfillment, and analytics tooling sees them normally.
2. What we hold — and what we don’t
| Store | Contents | Sensitive? |
|---|---|---|
| App database (session) | Shop domain, the offline access token issued by Shopify, granted API scopes | Access token is sensitive — it grants Admin API access |
| App database (offers, subscriptions) | Shopify GIDs, subscription status, next-billing date | No raw customer PII |
| Shopify (source of truth) | Customer name, address, payment method, orders, contracts | Held by Shopify, accessed via API — never stored at rest by Curobi |
The most sensitive secret Curobi holds is a store’s offline access token. It is treated as such — see access control and incident response below.
3. Encryption
- In transit: all connections to Shopify and to our database use TLS, and the app is served exclusively over HTTPS.
- At rest: our database provider encrypts stored data and backups at rest.
4. Access control & environment separation
- Production credentials are tightly restricted and protected by strong, unique passwords and two-factor authentication.
- Development and production run on separate deployments, databases, and credentials, so test activity can never touch live store data.
- Curobi requests only the Shopify API scopes it needs to function — and, under Shopify’s Protected Customer Data rules, only the Name and Address protected fields, never email or phone.
5. Access logging
Each time customer data is accessed, Curobi emits a PII-free, structured log recording who/what/when — never the data values themselves. Layered on our platform logs (hosting and database), these give us the trail needed to scope any incident without creating a new store of personal data.
6. Incident response
Curobi maintains a documented security-incident and breach-notification procedure. Incidents are triaged by severity and handled on a defined timeline:
| Level | Definition | Response starts |
|---|---|---|
| SEV-1 | Confirmed exposure of access tokens, API secret, or customer PII | Immediately (< 1 hour) |
| SEV-2 | Suspected exposure, or unauthorized infrastructure access with no confirmed data loss | < 12 hours |
| SEV-3 | Vulnerability, dependency CVE, or misconfiguration with no active exploitation | < 3 business days |
Our process is detect & record → contain (rotate secrets, revoke/reissue tokens, take the affected surface offline) → assess the blast radius using access and platform logs → notify → remediate the root cause → post-incident review with a new preventive control.
7. Breach notification
Curobi acts as a data processor on the merchant’s behalf. On a confirmed personal-data breach we notify affected merchants (the data controllers) without undue delay, with what happened, the data categories involved, and remediation — fast enough that they can meet their own regulatory clocks, including the GDPR 72-hour window. We also notify Shopify promptly through its Partner/Trust channels, and we keep a record of the breach and our response.
8. Sub-processors
Curobi relies on a small number of trusted providers — Shopify (platform and billing), our database host, application hosting, and transactional email. Each processes data only as needed and is bound by appropriate data-protection terms. The current list, with purpose and region, is maintained in our Privacy Policy.
9. Data-subject requests & deletion
Curobi honors Shopify’s mandatory data-privacy webhooks: customer data requests, customer redaction, and shop redaction after uninstall. Deletions are completed within 30 days, and because we store no raw customer PII, there is little to export or erase beyond the identifiers tied to an active subscription. Full detail is in thePrivacy Policy.
10. Responsible disclosure
If you believe you’ve found a security vulnerability in Curobi, please report it to us privately so we can address it before any public disclosure. Emailhello@curobi.com with steps to reproduce and any relevant details. We’ll acknowledge your report, keep you updated, and we’re grateful for good-faith research that helps keep merchants safe.
Curobi is operated by Vibhora. Curobi is not affiliated with or endorsed by Shopify Inc.
6 months free, on us.
The first 50 stores to install Curobi get 6 months of full access — every feature and 0% transaction fees — completely free. No card required, no catch.
Reserve your spot
Tell us where to reach you and we'll lock in your founding-merchant offer.
You're on the list.
Thanks — we've got your details and we'll be in touch to lock in your spot.
