Install

Security & incident response

Last updated: September 28, 2026

How Digital Executive Partner protects merchant and customer data in Zoho CRM Sync.

Data we hold

DataWhyRetention
Shopify and Zoho access tokensTo run the syncDeleted on uninstall / disconnect
Shopify ID ↔ Zoho CRM ID mappingsUpdate the same record, avoid duplicatesUntil uninstall (+ max 48 h)
Sync activity log (event type, record ID, result)Show sync status and errorsLatest 300 events per store; deleted on uninstall
Support requests (message, reply email)Answer support questionsDeleted on uninstall; resolved requests kept at most 12 months
Audit log (admin access, changes)Security monitoring12 months

Customer names, emails, phone numbers, addresses and order contents pass through the app to the merchant's Zoho CRM and are not stored by the app.

Protection measures

Incident response

  1. Detect & triage — alerts, audit log review or reports to digitalexecutivepartner@gmail.com are assessed within 24 hours.
  2. Contain — revoke affected Shopify/Zoho tokens, rotate secrets (encryption key, client secrets, database password), block access.
  3. Investigate — use the audit log and provider logs to find scope, affected stores and data.
  4. Notify — inform affected merchants and Shopify without undue delay and within 72 hours, with what happened, what data was affected and what to do.
  5. Recover & improve — restore service, document the incident and fix the root cause.

Report a vulnerability

Email digitalexecutivepartner@gmail.com with details. Please do not access data that is not yours.