Security & incident response
Last updated: September 28, 2026
How Digital Executive Partner protects merchant and customer data in Zoho CRM Sync.
Data we hold
| Data | Why | Retention |
|---|---|---|
| Shopify and Zoho access tokens | To run the sync | Deleted on uninstall / disconnect |
| Shopify ID ↔ Zoho CRM ID mappings | Update the same record, avoid duplicates | Until uninstall (+ max 48 h) |
| Sync activity log (event type, record ID, result) | Show sync status and errors | Latest 300 events per store; deleted on uninstall |
| Support requests (message, reply email) | Answer support questions | Deleted on uninstall; resolved requests kept at most 12 months |
| Audit log (admin access, changes) | Security monitoring | 12 months |
Customer names, emails, phone numbers, addresses and order contents pass through the app to the merchant's Zoho CRM and are not stored by the app.
Protection measures
- Encryption: HTTPS/TLS for all traffic; access tokens encrypted with AES-256-GCM; database and backups encrypted at rest by the hosting provider.
- Verification: every Shopify webhook and session token is signature-checked; OAuth uses single-use state tokens.
- Access control: only the app owner can access the admin area; strong password policy (min. 12 characters, letters and numbers/symbols), lockout after 5 wrong attempts, 12-hour sessions, and two-factor authentication on hosting, database and Shopify Partner accounts.
- Audit logging: admin logins (including failures), viewing shop data or support requests, plan changes, merchant settings and connection changes, and Shopify data requests are logged.
- Separation: development and testing use a separate database with test data; production data is never used for testing.
- Data loss prevention: data minimisation (no customer contents stored), encrypted secrets, least-privilege API scopes (read-only on Shopify), automatic deletion on uninstall, and provider-managed point-in-time backups.
Incident response
- Detect & triage — alerts, audit log review or reports to digitalexecutivepartner@gmail.com are assessed within 24 hours.
- Contain — revoke affected Shopify/Zoho tokens, rotate secrets (encryption key, client secrets, database password), block access.
- Investigate — use the audit log and provider logs to find scope, affected stores and data.
- Notify — inform affected merchants and Shopify without undue delay and within 72 hours, with what happened, what data was affected and what to do.
- Recover & improve — restore service, document the incident and fix the root cause.
Report a vulnerability
Email digitalexecutivepartner@gmail.com with details. Please do not access data that is not yours.