Trust

Security at Shipio

Shipio connects to the sales channels sellers rely on, so store credentials and order data are handled with a small, explicit set of practices. This page describes how we operate today and how to reach us about a security issue.

Last updated 18 August 2026

Accounts and authentication

  • Authentication is handled by a managed identity provider; Shipio never stores plaintext passwords.
  • Sessions use short-lived access tokens and every server request is authorised against the signed-in account.
  • Each seller only reaches their own records: private tables are protected by row-level access rules enforced by the database, not by the interface.

Connected stores and access tokens

  • Channel connections use the official OAuth flow of each platform (Shopify and Etsy). We never ask for a store password.
  • Access tokens are stored server-side only and are never sent to the browser or embedded in frontend code.
  • We request the minimum scopes needed to import products, publish listings and process orders.
  • When an app is uninstalled, the stored credentials for that store are deleted automatically.

Data handling

  • All traffic to Shipio is served over HTTPS.
  • Buyer data is limited to what an order needs: name, contact and delivery address, used for personalization, fulfillment and delivery.
  • Data-deletion and data-request webhooks from connected platforms are verified and processed automatically.
  • Secrets and API keys live in the server environment and are never exposed to client bundles.

Webhooks and integrations

  • Every incoming webhook is verified with an HMAC signature before its payload is read.
  • Requests that fail verification are rejected before any data is written.
  • Integration activity is recorded in an internal event log for auditing and support.

Reporting a vulnerability

If you believe you have found a security issue, email geral@myshipio.com with the details and steps to reproduce. We aim to acknowledge reports within 2 business days and will keep you updated while we investigate. Please do not publicly disclose an issue before we have had a chance to address it, and do not access or modify data that is not yours while testing.