Last updated: July 17, 2026. Report suspected security issues involving Cart Marshal to support@fiveacrecode.com with subject prefix [SECURITY].
Scope
In scope: Cart Marshal systems operated by Five Acre Code, including the embedded Shopify app server, database, Shopify Function configuration, app-owned merchant data handling, production credentials, and public Cart Marshal policy/support pages.
Out of scope: merchant-owned Shopify stores, Shopify platform systems, Shopify Checkout itself, merchant staff accounts, third-party apps, third-party services outside Five Acre Code control, and issues caused by merchant configuration.
Data used
Cart Marshal uses the following data to operate the app:
- Shopify OAuth/session data and merchant access tokens required to call approved Shopify APIs.
- Merchant shop identifiers, store profile details, active plan state, and app settings.
- Rule configuration, lifecycle state, Shopify resource IDs, sync status, timeline entries, and audit metadata.
- Product, tag, collection, customer, market, shipping, payment, delivery, validation, and cart transform data needed to configure or publish rules.
- Runtime checkout fields supplied to Shopify Functions when rules require them, such as cart contents, delivery country, customer email, customer tag matching, customer ID, order count, B2B company context, address lines for PO Box detection, and ZIP/postal code.
Data stored
Cart Marshal stores merchant app configuration, rule definitions, settings, lifecycle and audit records, comments entered by authorized store users, encrypted Shopify session data, billing-plan cache, limited Shopify privacy-request metadata, support messages, and operational/security logs.
Cart Marshal does not store customer payment card numbers, saved payment credentials, end-customer profiles, full order history, customer phone numbers, or customer browsing behavior. It does not copy customer email addresses from Shopify Checkout or Shopify customer profiles into its app database.
If you enter a customer email address or other personal data in a rule condition, label, message, audit comment, or support request, Cart Marshal stores that merchant-provided content as part of the rule, audit trail, or support record.
Checkout runtime fields used by Shopify Functions are evaluated at runtime and are not stored by Five Acre Code as customer profiles.
Practices
- HTTPS/TLS for app traffic.
- Shopify OAuth, embedded app authentication, and Shopify-managed session handling.
- Shopify webhook verification and duplicate-delivery handling.
- Encrypted Shopify session storage and production secrets kept outside source control.
- Least-necessary Shopify scopes for app functionality.
- Required Shopify privacy webhooks for customer data request, customer deletion, and shop deletion.
- Runtime-only handling of checkout customer fields inside Shopify Functions where possible.
- Structured operational logging with request IDs and sensitive-token scrubbing.
- Optional Sentry error monitoring with PII disabled and token scrubbing when configured.
- Production hosting and database services selected for managed infrastructure controls.
- Dependency and security alert triage through development tooling.
Merchant responsibilities
Merchants remain responsible for Shopify account security, staff permissions, installed apps, store configuration, rule review, rule publishing, rule testing, customer notices, and legal compliance. Cart Marshal cannot secure a merchant's Shopify account or prevent losses caused by merchant configuration, staff actions, third-party apps, Shopify outages, platform behavior, or unauthorized access outside Five Acre Code systems.
Response
Five Acre Code triages confirmed reports, contains the issue, rotates credentials where needed, reviews affected systems and providers, patches or rolls back, notifies affected parties when required, and performs post-incident review for significant incidents.
Severity targets:
| Severity | Examples | Triage target |
|---|---|---|
| Critical | Confirmed active compromise, public credential leak, confirmed external exposure of merchant data | Under 1 hour |
| High | Credible unauthorized access, contained secret exposure, security defect affecting production data | Under 4 hours |
| Medium | Non-exploited vulnerability, suspicious pattern under investigation, dependency advisory affecting production | Under 24 hours |
| Low | Hardening issue or informational report | Under 5 business days |
Notification timing depends on confirmation, affected data, applicable law, Shopify requirements, and merchant impact. Confirmed incidents involving Shopify-issued credentials, merchant data, or customer data are escalated through Shopify Partner Support where required.
Reporting guidelines
Please include the affected shop domain, app URL or route, reproduction steps, screenshots or request IDs if available, and whether you believe data was accessed or modified. Do not include secrets, access tokens, or unnecessary customer personal data in the initial report.