Skip to main content
TierFlow TierFlow™
How it works Features Pricing FAQ Walkthrough Contact Us Install Free

Security at TierFlow

Last updated: September 5, 2026

TierFlow is designed to handle merchant and Shopify data responsibly. We use technical and operational safeguards intended to protect the confidentiality and integrity of information processed by the service. This page describes those safeguards in general terms. It is not an exhaustive description of our infrastructure, and it is not a certification.

Data protection

TierFlow limits the data it collects and retains to information needed to provide and improve the service. In normal operation that means your Shopify shop domain, your product and tier configuration, and order-level records used to attribute revenue to TierFlow pricing.

Protected customer data, where enabled for an approved feature, is used only for the purposes described in our Privacy Policy and subject to applicable Shopify requirements.

Encryption in transit

Connections between TierFlow, Shopify, and your browser use TLS. Our communication with the Shopify Admin API, the TierFlow application itself, and outbound transactional email all run over encrypted connections.

Data at rest is held by our infrastructure providers and is subject to their security controls. We describe provider responsibilities in our Privacy Policy rather than making specific claims about storage or backup encryption on their behalf.

Access control

TierFlow is owner-operated. Access to production systems and to merchant information is restricted to authorized operational access, and administrative access is limited to a single account.

Administrator sign-in requires both a password and a time-based one-time passcode from an authenticator app. Passwords are subject to a minimum length requirement and are stored only as salted hashes. Sign-in attempts are rate limited, and administrative sessions expire automatically.

Application security

  • Shopify OAuth. TierFlow authenticates to your store through Shopify's OAuth flow and holds scoped access tokens rather than store credentials.
  • Webhook verification. Every webhook TierFlow receives from Shopify is HMAC-verified before any of its contents are processed. Requests that fail verification are rejected.
  • Administrator authentication. Password plus mandatory TOTP multi-factor authentication, with rate limiting and scoped, expiring sessions.
  • Secret management. Credentials and API keys are supplied to the application through environment configuration. They are not committed to source control.
  • Least data by design. TierFlow requests only the Shopify access scopes its features require.

Data retention and deletion

TierFlow receives and responds to Shopify's privacy webhooks for customer data requests, customer redaction, and shop redaction. When a merchant uninstalls and Shopify signals shop redaction, TierFlow deletes the shop's access tokens and merchant contact information.

We are actively reviewing and improving our retention and deletion procedures, including the handling of order-level records after a deletion request. We would rather describe that work accurately than claim it is finished. Our Privacy Policy is the authoritative statement of what we retain, and we are updating it alongside this work.

Incident response

TierFlow maintains a written incident response process for investigating and responding to suspected security events. It covers detection, containment, credential rotation, investigation, remediation, and any notifications required under Shopify, contractual, or legal obligations.

A suspected incident is investigated even when a compromise has not been confirmed, and the process is reviewed after any material incident.

Service providers

TierFlow relies on a small number of providers to operate: Shopify as the commerce platform, Railway for application hosting and our database, Google for transactional email, and GitHub for source code. Their roles and the data they process are described in our Privacy Policy.

Reporting a security issue

If you believe you have identified a security issue involving TierFlow, please contact us at care@tierflow.app.

Please include enough detail for us to reproduce and investigate the issue. Do not include customer personal information, passwords, API keys, access tokens, or other secrets in your report. We appreciate reports made in good faith and will not pursue action against researchers who report responsibly and avoid accessing or altering data that is not their own.

For details of what data TierFlow collects, how it is used, and your rights, see our Privacy Policy and Terms of Service.

TierFlow TierFlow™
How it works Features Pricing FAQ Walkthrough Privacy Policy Terms of Service Security Contact Us

© 2026 TierFlow. All rights reserved. · tierflow.app