Appearance
Security Policy for Garnet Marketplace
1. Data Handling
Our Shopify app processes and manages the following types of data:
- Customer Data: Includes personal details such as names, email addresses, and contact information
- Payment and Payout Data: Order totals, commission and vendor payout amounts. We do not store payment card details — card data is handled entirely by our payment providers (Stripe, Mollie) and never reaches Garnet systems
- Order Details: Involves information related to customer orders, including product information, quantities, and order statuses
2. Data Protection
Sensitive data is protected using the following measures:
- Encryption in transit: All data transmission uses TLS
- Encryption at rest: Our database and its backups are encrypted at rest
- Application-layer encryption: Order customer records, email addresses, telephone numbers and billing and shipping addresses are additionally encrypted before being written to the database. Customer names, and customer email addresses within the messaging feature, are stored unencrypted because they are needed for search and message delivery
- Access Controls: Strict access controls are implemented to ensure only authorized personnel can access sensitive data
3. Authentication
Access to the app is secured through:
- Passwords: User accounts are protected by strong passwords, and password policies are enforced to ensure security
4. Data Transmission
To ensure secure communication between our app and Shopify:
- HTTPS: All data transmissions are conducted over HTTPS to provide a secure connection
- Secure APIs: APIs are designed to be secure and protected against unauthorized access
- Network controls: Production infrastructure runs in a dedicated Virtual Private Cloud with security-group access controls, and database connections require TLS
5. Data Integrity
To maintain data integrity and prevent tampering:
- Webhook Checksums: Webhooks are validated using checksums to ensure data integrity and prevent unauthorized modifications
6. Vulnerability Management
We manage and address security vulnerabilities through:
- Regular Updates: The app is updated regularly to address security vulnerabilities and improve protection
- Vulnerability Scans: Regular scans are conducted to identify and address potential security issues
7. Access Control
Access within the app is managed by:
- Permissions: User access within the application is controlled through a role and permissions model, so that marketplace operators and vendors access only the data and functions relevant to their role
- Administrative access: Multi-factor authentication is required on all interactive accounts with access to production systems
8. Logging and Monitoring
To detect and respond to security incidents:
- Logging User Activity: User activity is logged to track actions and identify suspicious behavior
- Continuous threat detection: AWS GuardDuty analyses network, DNS and API activity continuously, and all management-plane activity is recorded to an integrity-validated audit trail
- Error monitoring: Application errors are captured and alerted on. We do not currently operate independent availability monitoring
9. Incident Response
In the event of a security breach or data leak:
- Notification: Notify us immediately at support@garnetmarketplace.com
- Response Time: We will respond to reported incidents within 48 hours to address and remediate the issue
10. Compliance
We are committed to compliance with relevant data protection regulations and standards to ensure that all data handling adheres to legal and industry requirements.
Further detail on our security controls, including our disaster recovery testing, incident response process and sub-processor arrangements, is available to customers and prospective customers on request.
Last reviewed: 19 August 2026.