As of August 24, 2026. This policy describes security practices for Shopify consulting, theme customization, development, migration, launch, and ongoing-support services provided by HansonCore, LLC DBA Five Acre Code.
Scope
This policy covers project systems, source code, credentials, Client information, and Shopify access controlled by Five Acre Code during a service engagement. Shopify, Client systems, third-party themes, apps, repositories, providers, staff accounts, and devices outside our control remain the responsibility of their owners.
Access practices
- Prefer Shopify collaborator accounts, properly scoped staff roles, or Theme Access over shared passwords.
- Request only permissions required for the agreed work and reduce or remove access when it is no longer needed.
- Use named user accounts and multi-factor authentication where the platform supports it.
- Do not request payment card data, customer passwords, Shopify owner passwords, or unrelated production secrets.
- Do not place active credentials in public forms, ticket subjects, ordinary screenshots, source repositories, or project documentation.
- Use approved secret-sharing or platform invitation flows when a credential is unavoidable.
Development and release practices
- Inventory the live theme, relevant apps, integrations, and known customizations before consequential work.
- Develop in a Shopify development theme, unpublished theme, preview, draft, or other non-live surface when available.
- Use Shopify CLI, Theme Check, source control, and focused review/testing in proportion to the change and engagement.
- Preserve the original failure evidence and an available rollback path before a repair or publication.
- Publish or mutate production only with authority established by the scope or an authorized Client approval.
- Record material release behavior, remaining risks, third-party dependencies, and the handoff owner.
Shopify's GitHub integration can synchronize theme changes in both directions. When used, repository access, connected branches, Shopify-admin edits, publication behavior, and ownership must be agreed so an automatic commit or branch update does not bypass the release process.
Project data
We minimize copies of production data and use representative or synthetic test content where practical. Theme work can still expose storefront, admin, product, company, order, or customer information visible to the authorized account. Access is limited to the engagement purpose.
Theme files, code, logs, exports, screenshots, recordings, and test evidence must exclude credentials and unnecessary personal data. Temporary project artifacts are returned, deleted, or access-revoked when no longer needed, subject to the written agreement and reasonable legal/security retention.
Client responsibilities
The Client is responsible for account ownership, staff access, multi-factor authentication, lawful data/content, licenses, backups, recovery, platform/app configuration, approval of releases, and notifying Five Acre Code of suspected compromise or material changes.
The Client must not disable security controls, ask Five Acre Code to share accounts, provide more access than required, or publish unreviewed work while representing it as accepted. More detail is in Store Access and Client Responsibilities.
Vulnerability and incident reporting
Report a suspected vulnerability, credential exposure, unauthorized access, or project-related security event to support@fiveacrecode.com with subject prefix [SECURITY].
Include the affected store/system, impact, time with timezone, steps to reproduce, and safe supporting evidence. Do not include active passwords, access tokens, payment card data, or unnecessary customer information in the initial message.
Response
We triage confirmed credential exposure, unauthorized production access, customer or merchant data exposure, source-code compromise, and active storefront disruption. Response can include containment, credential revocation/rotation, access review, evidence preservation, code or configuration changes, rollback, provider coordination, Client notification, and post-incident review.
Notification timing and responsibilities depend on the incident, affected data, controller/processor roles, law, Shopify requirements, and the signed agreement. We do not promise a fixed incident outcome or provider response outside an express written service level.
Exclusions
Security consulting does not by itself include penetration testing, compliance certification, payment-card assessment, legal advice, continuous monitoring, a managed security operations center, or a guarantee against compromise. Any additional security service must be expressly included in a signed agreement.
Contact
Security: support@fiveacrecode.com with [SECURITY] in the subject.