Legal & data

Incident Response

How to report a concern and the process for assessment, containment, notification and recovery.

Last updated

All policies

1. Report a concern

Email support@customerhubapp.com with “Security incident” in the subject. Describe the affected store or service, the time, what you observed and how we can contact you. Share only the minimum information needed; do not include passwords, tokens or unnecessary customer records.

If you suspect a Shopify staff account or connected service is compromised, also follow the relevant provider’s recovery process. Do not attempt intrusive testing or access to another merchant’s information.

2. Assess and coordinate

Our response process begins by recording the report, assigning a responsible technical contact and assessing affected systems, personal information, likely impact and urgency. The response preserves relevant evidence, involves appropriate support/management contacts and coordinates with service providers where necessary.

3. Contain and investigate

Depending on the incident, measures may include limiting an affected function, revoking compromised access, correcting configuration or isolating a component. Investigation seeks to establish scope and cause while protecting other merchants and avoiding unnecessary exposure of personal information.

4. Communicate and meet legal duties

Where an incident affects personal data processed for a merchant, CustomerHub must follow the applicable agreement and law, including notifying the merchant without undue delay where required. Information may be provided in stages as facts become available.

The relevant parties must assess any regulator and individual-notification requirements. This overview does not replace mandatory notification duties or set a universal regulatory deadline for every incident.

5. Recover and review

The response addresses the cause, restores affected service safely, verifies recovery and monitors for recurrence. A documented review records the impact, corrective actions and lessons for future response. Readiness exercises and review frequency follow the applicable operational plan.

6. Scope of this overview

This overview explains our incident-response process. It does not provide an uptime guarantee, a fixed response-time SLA or a guarantee that every incident can be resolved within a set period. Any separately agreed contractual commitments continue to apply.

For security questions, contact support@customerhubapp.com. See also Data Security and the Privacy Policy.

Questions about this document?

support@customerhubapp.com