Torevo Security

Security for Torevo products and projects.

Security measures reflect the data, permissions and external services actually used by each product or client project.

A. Core security measures

Data protection from transfer through deletion.

We use encrypted transport, limited permissions, separated access and defined retention rules.

Encrypted transport and security headers

The public configuration enforces HTTPS, HSTS, restricted content sources, frame blocking and safe content-type handling.

Secrets kept out of the public client

The static website contains public configuration only. SMTP passwords, Shopify secrets and provider tokens are excluded from the client bundle and analytics events.

Documented minimum Shopify permissions

Shipping and KROS profiles record permissions separately according to the objects they process. Any scope expansion requires a separate review.

Separated product identities and data namespaces

Individual Shopify identities use separate credentials, public URLs, encryption keys and database namespaces.

Privacy and lifecycle handlers

Mandatory Shopify privacy and app-lifecycle handlers process data requests and uninstall events.

Deletion process and maximum retention

Uninstall, a merchant request or loss of purpose starts the applicable deletion process. A legal duty may require restricted retention.

B. Product-specific measures

Data and permission scope differs by product.

Each product lists its Shopify permissions, processed data, external services, maximum retention and uninstall procedure.

Torevo • KROS Fakturácia

Shopify scopes
read_orders, read_companies, read_customers
Processed data objects
  • orders, refunds and transactions
  • customer and company billing data
  • documents, payments, operation state and PDF files
External services and recipients
  • DigitalOcean as hosting subprocessor
  • Shopify as the merchant platform
  • KROS as a merchant-connected provider
Maximum retention
Webhook and job metadata for up to 30 days, callback metadata for up to 90 days, security audit data for up to 365 days and encrypted backups for up to 30 days. Document metadata and encrypted PDFs for up to 2,555 days unless purpose or a request requires earlier deletion.
After uninstall
Uninstall triggers the lifecycle handler and the applicable deletion process. Data subject to a legal duty remains restricted to that purpose.
Privacy webhooks
The app handles mandatory Shopify privacy webhooks and uninstall events.
Incident reporting
Report via torevo@torevo.tech without passwords, tokens or customer personal data.

Torevo Shipping

Shopify scopes
read_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_orders
Processed data objects
  • orders and line items
  • delivery data required for a shipment
  • fulfillment orders
  • shipments, labels and tracking
External services and recipients
  • DigitalOcean as hosting subprocessor
  • Shopify as the merchant platform
  • carrier enabled by the merchant
Maximum retention
Webhook and job metadata for up to 30 days, callback metadata for up to 90 days, security audit data for up to 365 days and encrypted backups for up to 30 days.
After uninstall
Uninstall triggers the lifecycle handler and the applicable deletion process. Data subject to a legal duty remains restricted to that purpose.
Privacy webhooks
The app handles mandatory Shopify privacy webhooks and uninstall events.
Incident reporting
Report via torevo@torevo.tech without passwords, tokens or customer personal data.

Torevo • Packeta SK

Shopify scopes
read_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_orders
Processed data objects
  • orders and line items
  • delivery data required for a shipment
  • fulfillment orders
  • shipments, labels and tracking
External services and recipients
  • DigitalOcean as hosting subprocessor
  • Shopify as the merchant platform
  • Packeta Group as the carrier enabled by the merchant
Maximum retention
Webhook and job metadata for up to 30 days, callback metadata for up to 90 days, security audit data for up to 365 days and encrypted backups for up to 30 days.
After uninstall
Uninstall triggers the lifecycle handler and the applicable deletion process. Data subject to a legal duty remains restricted to that purpose.
Privacy webhooks
The app handles mandatory Shopify privacy webhooks and uninstall events.
Incident reporting
Report via torevo@torevo.tech without passwords, tokens or customer personal data.

Torevo • Zasilkovna

Shopify scopes
read_orders, read_merchant_managed_fulfillment_orders, write_merchant_managed_fulfillment_orders
Processed data objects
  • orders and line items
  • delivery data required for a shipment
  • fulfillment orders
  • shipments, labels and tracking
External services and recipients
  • DigitalOcean as hosting subprocessor
  • Shopify as the merchant platform
  • Packeta Group as the carrier enabled by the merchant
Maximum retention
Webhook and job metadata for up to 30 days, callback metadata for up to 90 days, security audit data for up to 365 days and encrypted backups for up to 30 days.
After uninstall
Uninstall triggers the lifecycle handler and the applicable deletion process. Data subject to a legal duty remains restricted to that purpose.
Privacy webhooks
The app handles mandatory Shopify privacy webhooks and uninstall events.
Incident reporting
Report via torevo@torevo.tech without passwords, tokens or customer personal data.
C. Controls defined by project or agreement

These measures are not included automatically with every service.

Scope, measurement and ownership must be stated in the relevant order, SLA or security schedule. Without that agreement, Torevo does not present them as active controls.

SLA and response times

Agreed service windows, severity levels and communication procedure.

RPO and RTO

Recovery objectives only for a system with confirmed backup and recovery architecture.

Penetration testing

Scope, assessor, schedule and handling of findings.

Dedicated infrastructure

Account, network, data or operational-role isolation for the project.

Specific retention

Periods that differ from product defaults and the legal reason for retention.

Contractual audits

Evidence scope, frequency and rules for protecting confidential information.

D. Reporting a security issue

Send a safe reproduction path, not sensitive data.

Send security reports to torevo@torevo.tech.

  • Do not send passwords, tokens, API keys or other secrets.
  • Do not send customer personal data or unredacted production exports.
  • Do not disclose the issue or exploitation steps before it has been handled safely.
  • Include the affected URL or component, expected result and a safe reproduction path.
  • Do not change or delete production data and do not use third-party accounts.
Send a security report
Security

Need to define the security scope of a project?

The initial assessment separates product controls, project requirements and evidence required before deployment.