Security & data

How we handle your data

Route to Ship is a Shopify app that processes order and production data on your behalf. This page describes, in plain terms, how that data is protected. We state only what we actually do — we make no formal certification claims.

Hosting & encryption

The application is hosted on Vercel and stores data in a managed PostgreSQL database. All traffic is served over HTTPS/TLS (encrypted in transit), and data is encrypted at rest by our infrastructure providers.

Authentication

Access to your Shopify data uses Shopify's OAuth token-exchange flow with short-lived, automatically refreshed tokens — there are no long-lived credentials stored. Incoming Shopify webhooks are verified by HMAC signature before they are processed.

Payment data

Billing runs entirely through Shopify Billing. Route to Ship never sees or stores your card or payment details.

Privacy & data deletion

Your data is never sold or shared for marketing. Route to Ship implements Shopify's mandatory compliance webhooks — customer data request, customer redact, and shop redact — so customer-data and store-deletion requests are honoured, and your data is removed when you uninstall the app. See our Privacy Policy.

Subprocessors

  • Shopify — platform, order data, and billing
  • Vercel — application hosting
  • Prisma — managed PostgreSQL database
  • Resend — transactional email (e.g. customer tracking notifications)

Reporting a concern

Found a security issue or have a data question? Email support@routetoship.com and we'll respond within one business day.