Security

Built to touch as little as possible

The safest data is data we never hold. Fluttify's architecture keeps payments, passwords, and admin control where they belong, with Shopify and you.

How Fluttify handles your data

Scoped, read-only access

Store access uses Shopify's authorization flow with the narrowest scopes that can build your app: theme, catalog, menus. We never request write access to your store, and we never ask for your admin password. Revoke access anytime from your Shopify admin.

Payments never touch us

Checkout hands off to Shopify's own checkout. Cards, wallets, taxes, and fraud protection run on Shopify rails end to end, Fluttify systems process no payment data, ever.

Shopper sign-in via OAuth

Customer login uses Shopify's customer authentication with industry-standard OAuth and PKCE. Your shoppers' credentials go to Shopify, not to Fluttify, and not to the app's storage.

Secrets handled properly

Per-store credentials live in a managed secrets store, encrypted at rest and in transit, injected only at build time, never committed to code, never shared between merchants.

One audited engine

Every app is built from the same reviewed, tested commerce engine, no per-store generated code, no unvetted dependencies. Static analysis and automated tests gate every single build.

You stay in control

Apps ship under your Apple and Google accounts. Disconnecting Fluttify revokes our access, and synced store data is deleted from our systems within 30 days.

Responsible disclosure

Found a vulnerability? We run a responsible-disclosure process and respond within 48 hours.

info@fluttify.in

See also: Privacy Policy · Terms & Conditions