Salesreach
Security & Incident Response
Effective August 28, 2026
This page describes the technical and organizational measures Revotech OĆ applies to protect personal data processed through Salesreach, and what happens if something goes wrong.
1. Data protection measures
- Encryption in transit: all traffic to and from Salesreach, and between Salesreach and its sub-processors, is encrypted (HTTPS/TLS).
- Encryption at rest: our database is hosted on a managed provider that encrypts stored data at rest.
- Access control: our internal admin tooling, which can access Customer data across connected stores, requires authentication and is not reachable by merchants or the public. Every successful access is logged (who, what, when).
- Password requirements: internal admin accounts require a minimum 12-character password.
- Environment separation: demo/test data used for internal testing and app review is kept separate from real merchant and Customer data.
- Retention limits: personal data is not kept longer than described in our Privacy Policy's retention schedule ā inactive conversations are automatically deleted, not kept indefinitely.
- Webhook integrity: every webhook we receive from Shopify is verified against its HMAC signature before being trusted.
2. Security incident response
If we become aware of a security incident that may affect personal data we process:
- Detect and contain: we investigate and take immediate steps to contain the issue (e.g. revoking a compromised credential, patching a vulnerability).
- Assess: we determine what data and which Merchants/Customers were potentially affected.
- Notify: we notify affected Merchants without undue delay, so they can meet their own notification obligations to Customers or regulators where required.
- Remediate and review: once contained, we address the root cause and review whether additional safeguards are needed to prevent recurrence.
3. Report a security issue
If you believe you've found a security vulnerability in Salesreach, please email support@salesreach.net with details. We ask that you not publicly disclose the issue until we've had a reasonable opportunity to address it.