Skip to content
NarrowForge

NF / Legal / Shopify

Bulk Gift Orders — Security

1. Scope

This policy describes the security boundary for Bulk Gift Orders, an embedded Shopify app that creates orders or draft orders from merchant-reviewed recipient batches. It describes the controls and limits in the current release; it is not a security certification.

2. Least-privilege Shopify access

The app requests the scopes required for its documented workflow:

  • read_products — match SKUs, barcodes, variants and prices.
  • read_orders and read_draft_orders — find deterministic tags during safe retries.
  • write_draft_orders and write_orders — create only the draft or order the merchant starts after review.

The app does not request theme, checkout or customer-management scopes. Recipient contact fields supplied by a merchant are used only because the destination order may need them.

3. Authentication and tenant isolation

Shopify OAuth and authenticated admin requests establish the store context. Server-side loaders, actions, jobs and report downloads scope data by the authenticated shop; a browser-supplied shop identifier is not treated as an authorisation boundary. Secrets and Shopify session credentials stay on the server.

4. Write safety and idempotency

Creation is merchant-triggered after preflight. Each recipient is claimed atomically and linked to one result. Retries search the deterministic batch tag before creating again, and the queue records audit events and retry state. Financial status is fail-closed to an explicit merchant choice rather than inferred from uploaded text.

5. Webhooks, logging and failure handling

Shopify webhook signatures are verified before processing and delivery identifiers are handled idempotently. API errors, rate limits, missing permissions and invalid rows are surfaced as review or blocked states instead of being converted into a clean success. Application logs redact credential-like and customer-like fields, and optional error reporting is configured without attaching recipient payloads.

6. Vulnerability disclosure

Report a suspected security issue privately through the support form with category Security, or email support@narrowforge.com. Include a short description, reproduction steps, affected feature and expected impact. Do not include credentials, tokens or unnecessary personal data, and do not disclose the issue publicly before it has been reviewed.

7. Certifications and contact

Bulk Gift Orders does not currently claim SOC 2, ISO 27001 or another formal security certification. If that changes, the scope and effective date will be stated here. Related: privacy · terms.

Last updated: 2026-09-12.