1. How responsibilities are shared
C:Hub renders the account experience and processes the data needed for enabled features. Shopify provides the underlying customer and commerce platform. CustomerHub also stores merchant information, app configuration, authentication/session records and operational information needed to run the service.
Merchants choose their account content, fields, integrations and customer-facing actions. Connected apps operate their own services. Security and privacy responsibilities therefore span C:Hub, Shopify, the merchant and the relevant providers.
2. Account access and requests
C:Hub uses Shopify authentication for the merchant administration experience and Shopify customer sign-in for storefront accounts. Protected service routes use authentication or signed-request validation appropriate to the operation. Account actions also depend on the applicable customer context and eligibility checks.
Public application destinations use HTTPS. The service retains tokens and session information where needed to call Shopify on behalf of an authorized store. Merchants should limit staff access and treat integration credentials as confidential.
3. Customer information and files
Profile updates and supported custom fields can update Shopify customer data and metafields. Recently viewed and saved-from-cart features can process product activity and browser storage. Some app and operational records are stored by CustomerHub; the service is not simply a display with no data processing.
Supported uploads may use Shopify-hosted files. Do not treat an account upload field as a private document vault or assume a linked file has restricted access. Use only information appropriate to the configured feature and intended visibility.
4. Providers and diagnostics
Cloud infrastructure, email, support and error-monitoring services may process relevant service information. The website contact handler keeps its email key on the server, checks submitted fields and screenshot types/sizes, restricts message destinations, and applies temporary sending limits and duplicate protection. It logs request references and provider status rather than enquiry contents. Error-monitoring configuration in the app includes filtering for common credential-related keys, but merchants should still avoid sending unnecessary personal information or secrets in support messages.
See the service-provider information for the identified services and the distinction between infrastructure providers and merchant-selected apps. This overview does not claim a certification, penetration-testing schedule, universal encryption-at-rest configuration or guaranteed recovery time.
5. Data requests and ending service
Customer data requests normally begin with the merchant. Shopify provides app privacy-request and redaction processes, and C:Hub’s app configuration routes those requests to its compliance service. A request’s full coverage and completion must be handled through the applicable operational process.
Uninstalling revokes app access but is not the same as deleting Shopify records or instantly erasing all related support and operational information. Contact support@customerhubapp.com for a request relating to CustomerHub-held data or for the security information needed to assess your use of the app.
6. Report a security concern
Email support@customerhubapp.com with “Security” in the subject. Include the affected store or URL, what happened, when it happened and safe reproduction details. Do not send passwords, access tokens or unnecessary customer information.
Our Incident Response overview describes the reporting and response process. A contractual response-time or availability commitment applies only where separately agreed.
Questions about this document?
support@customerhubapp.com