NF / Docs / Intrastat Europe
Security boundary
Permissions, tenant isolation, webhook verification and private exports.
Last updated: 2026-09-09
In this section
Shopify permissions
The app requests these read scopes for its documented job:
- read_orders — order, line-item, destination and refund data.
- read_products — product and variant identifiers and weight metadata.
- read_locations — fulfilment locations for a merchant-confirmed mapping.
- read_fulfillments — shipped quantities, dates and locations.
It does not request write access to orders, products, customers, themes or checkout. The sync query
does not request customer names, email addresses, phone numbers or street-address lines.
Tenant isolation
Shopify authentication establishes the store context. Application records are scoped to that
store, and server-side routes do not trust a browser-supplied shop id as an authorisation boundary.
Session tokens and application secrets stay on the server.
Fail closed and preserve evidence
Webhook signatures are verified before processing. Duplicate delivery identifiers are idempotent,
and incomplete Shopify connections become blocking issues instead of partial movements. Finalized
declarations and export artifacts carry SHA-256 hashes; the authenticated download route checks the
hash and store context before returning a file.
Read the full security policy, privacy policy
and data deletion page for the product-specific boundaries.