Trust
Security at Shipio
Shipio connects to the sales channels sellers rely on, so store credentials and order data are handled with a small, explicit set of practices. This page describes how we operate today and how to reach us about a security issue.
Last updated 18 August 2026
Accounts and authentication
- Authentication is handled by a managed identity provider; Shipio never stores plaintext passwords.
- Sessions use short-lived access tokens and every server request is authorised against the signed-in account.
- Each seller only reaches their own records: private tables are protected by row-level access rules enforced by the database, not by the interface.
Connected stores and access tokens
- Channel connections use the official OAuth flow of each platform (Shopify and Etsy). We never ask for a store password.
- Access tokens are stored server-side only and are never sent to the browser or embedded in frontend code.
- We request the minimum scopes needed to import products, publish listings and process orders.
- When an app is uninstalled, the stored credentials for that store are deleted automatically.
Data handling
- All traffic to Shipio is served over HTTPS.
- Buyer data is limited to what an order needs: name, contact and delivery address, used for personalization, fulfillment and delivery.
- Data-deletion and data-request webhooks from connected platforms are verified and processed automatically.
- Secrets and API keys live in the server environment and are never exposed to client bundles.
Webhooks and integrations
- Every incoming webhook is verified with an HMAC signature before its payload is read.
- Requests that fail verification are rejected before any data is written.
- Integration activity is recorded in an internal event log for auditing and support.
Reporting a vulnerability
If you believe you have found a security issue, email geral@myshipio.com with the details and steps to reproduce. We aim to acknowledge reports within 2 business days and will keep you updated while we investigate. Please do not publicly disclose an issue before we have had a chance to address it, and do not access or modify data that is not yours while testing.
