Security
How we protect your data, and what happens if something goes wrong.
This page is the plain-English version of the promises App Still Works makes to Shopify and to the merchants who install our apps. It is short because the setup is small: one person, one database, one hosting provider.
What protects the data
- Encryption. Data is encrypted on its way between your browser, the app, and its database, and it is encrypted again while it sits in the database.
- Least data. Each app stores only what its job needs. Still Works Standing Orders: the products, the day, the customer's name and email, and a delivery address when there is local delivery. Still Works Classes: the class, the date, the seats, the student's name, email, and phone, and whatever they typed at checkout. Neither ever holds card numbers. Shopify does.
- Separate environments. New work is built and tested against a database on the developer's own machine and a Shopify test store. Live store data is never copied into that test setup.
- Access logging. Every time customer data is read inside the app, whether by your staff, by a customer through their account, or by the billing system, a record is kept of who, what, and when.
- Backups and loss prevention. The database provider keeps a running history so a bad change can be rolled back. Every release is versioned, and any release can be undone in minutes.
- Accounts. The one person with access uses unique, strong passwords and two-step sign-in on every account: Shopify, the hosting provider, the database provider, and email.
If there is a security incident
An incident is any event where merchant or customer data may have been exposed, changed, or lost, or where the app charged someone it should not have.
- Contain within hours. Change the affected passwords and keys, cut off any access that may have been misused, and pause billing if billing is involved, so nothing else happens while we look.
- Assess within one business day. Use the access log, hosting logs, and database history to work out what was touched, by whom, and when.
- Notify affected merchants within 72 hours of confirming an incident, by email, with what happened, what data was involved, what we did, and what they may need to do. Merchants are responsible for telling their own customers where the law requires it, and we give them what they need to do that.
- Fix and write it up. The cause is fixed before service resumes, and a short note about what happened is published on this page.
To report a security concern, email jon@appstillworks.com with "Security" in the subject. Reports are read the same business day.
Incident history
None to date. This page was first published September 8, 2026.