Security

How we protect your data, and what happens if something goes wrong.

This page is the plain-English version of the promises App Still Works makes to Shopify and to the merchants who install our apps. It is short because the setup is small: one person, one database, one hosting provider.

What protects the data

If there is a security incident

An incident is any event where merchant or customer data may have been exposed, changed, or lost, or where the app charged someone it should not have.

  1. Contain within hours. Change the affected passwords and keys, cut off any access that may have been misused, and pause billing if billing is involved, so nothing else happens while we look.
  2. Assess within one business day. Use the access log, hosting logs, and database history to work out what was touched, by whom, and when.
  3. Notify affected merchants within 72 hours of confirming an incident, by email, with what happened, what data was involved, what we did, and what they may need to do. Merchants are responsible for telling their own customers where the law requires it, and we give them what they need to do that.
  4. Fix and write it up. The cause is fixed before service resumes, and a short note about what happened is published on this page.

To report a security concern, email jon@appstillworks.com with "Security" in the subject. Reports are read the same business day.

Incident history

None to date. This page was first published September 8, 2026.