Skip to content
NarrowForge

NF / Docs / Intrastat Europe

Security boundary

Permissions, tenant isolation, webhook verification and private exports.

Last updated: 2026-09-09

In this section

Shopify permissions

The app requests these read scopes for its documented job:

  • read_orders — order, line-item, destination and refund data.
  • read_products — product and variant identifiers and weight metadata.
  • read_locations — fulfilment locations for a merchant-confirmed mapping.
  • read_fulfillments — shipped quantities, dates and locations.

It does not request write access to orders, products, customers, themes or checkout. The sync query

does not request customer names, email addresses, phone numbers or street-address lines.

Tenant isolation

Shopify authentication establishes the store context. Application records are scoped to that

store, and server-side routes do not trust a browser-supplied shop id as an authorisation boundary.

Session tokens and application secrets stay on the server.

Fail closed and preserve evidence

Webhook signatures are verified before processing. Duplicate delivery identifiers are idempotent,

and incomplete Shopify connections become blocking issues instead of partial movements. Finalized

declarations and export artifacts carry SHA-256 hashes; the authenticated download route checks the

hash and store context before returning a file.

Read the full security policy, privacy policy

and data deletion page for the product-specific boundaries.