The safest data is data we never hold. Fluttify's architecture keeps payments, passwords, and admin control where they belong, with Shopify and you.
How Fluttify handles your data
Scoped, read-only access
Store access uses Shopify's authorization flow with the narrowest scopes that can build your app: theme, catalog, menus. We never request write access to your store, and we never ask for your admin password. Revoke access anytime from your Shopify admin.
Payments never touch us
Checkout hands off to Shopify's own checkout. Cards, wallets, taxes, and fraud protection run on Shopify rails end to end, Fluttify systems process no payment data, ever.
Shopper sign-in via OAuth
Customer login uses Shopify's customer authentication with industry-standard OAuth and PKCE. Your shoppers' credentials go to Shopify, not to Fluttify, and not to the app's storage.
Secrets handled properly
Per-store credentials live in a managed secrets store, encrypted at rest and in transit, injected only at build time, never committed to code, never shared between merchants.
One audited engine
Every app is built from the same reviewed, tested commerce engine, no per-store generated code, no unvetted dependencies. Static analysis and automated tests gate every single build.
You stay in control
Apps ship under your Apple and Google accounts. Disconnecting Fluttify revokes our access, and synced store data is deleted from our systems within 30 days.
Responsible disclosure
Found a vulnerability? We run a responsible-disclosure process and respond within 48 hours.