Limit access
Public-facing services are designed to expose only the actions required for a feature to work. Administrative reads, updates, and deletions are restricted.
Security at Reveu
Reveu applies practical security controls across its public website, Shopify application, data handling, storefront integrations, and privacy workflows.
Core principles
Reveu combines request verification, restricted data access, validation, privacy controls, and operational safeguards to reduce unnecessary risk.
Public-facing services are designed to expose only the actions required for a feature to work. Administrative reads, updates, and deletions are restricted.
Requests originating from Shopify integrations are checked before trusted actions are performed.
Public forms, application settings, imported content, URLs, and request data are validated before they are accepted or processed.
Reveu aims to collect only the information required to operate a feature, provide support, or meet legal and privacy obligations.
Reveu’s current security controls are designed around the information and integrations used by the public website and Shopify application.
Website form submissions cannot be publicly listed, read, edited, or deleted.
Shopify webhooks and app-proxy requests are checked before processing.
Form fields, settings, media URLs, and imported data are validated.
Uninstall and privacy workflows are connected to merchant and review-data cleanup processes.
01
This page describes the security approach currently applied to:
Reveu is still preparing for launch. Security controls, documentation, service providers, and operational procedures may continue to develop as testing progresses.
02
The public website collects a limited amount of information through the early-access waitlist and contact form.
Current website protections include:
Visitors should not submit passwords, authentication codes, payment-card information, or unnecessary sensitive personal information through the website.
03
Reveu uses Shopify application interfaces, webhooks, app proxies, theme app extensions, products, orders, customers, and fulfilment events to provide its merchant features.
Security measures applied to Shopify integrations include:
Reveu depends on Shopify services and interfaces. Shopify outages, API changes, access restrictions, or platform security events may affect Reveu even where Reveu’s own systems are operating normally.
04
Reveu aims to limit access to merchant, customer, review, and website-submission data to the systems and people that require it for legitimate operational purposes.
Current protections include:
Reveu’s handling of personal information is explained further in the Privacy Policy.
05
Reveu includes workflows intended to support Shopify privacy requirements and merchant-data cleanup.
These workflows include:
Privacy-processing errors are not intentionally hidden or silently treated as successful. This supports investigation and retry handling where required.
06
Reveu applies validation and defensive controls across review, email, import, storefront, and merchant-setting workflows.
Submission data, verification status, review-request tokens, customer media, and moderation settings are checked before processing.
Review-request delays are validated, provider failures are surfaced, and production sending is not treated as successful when no email provider is available.
Imported content is checked and matched using controlled product identifiers such as handles, product IDs, and SKUs.
Theme widgets use controlled settings and validation to reduce unsafe or unexpected storefront output.
Review media references are validated before trusted processing or deletion actions are performed.
Queue jobs and scheduled review requests use validated identifiers and explicit failure handling.
07
Reveu uses third-party infrastructure and technology services to operate the website and application.
These may include:
Reveu evaluates providers based on the service required, available security controls, data-processing needs, and operational suitability.
No internet or cloud service can guarantee complete protection against every security event. Third-party outages or incidents may also affect Reveu services.
08
Security is shared between Reveu, Shopify, service providers, and each merchant.
Merchants are responsible for:
Reveu will never require a merchant to send a Shopify password or authentication code through the public contact form.
09
If Reveu becomes aware of a suspected security incident, the response may include:
The exact response will depend on the nature, severity, scope, and likely impact of the incident.
10
Security researchers, merchants, and website visitors may report a suspected vulnerability or security issue directly to Reveu.
Include:
Do not access, alter, download, disclose, or destroy data belonging to another person. Do not disrupt the website, application, Shopify stores, or third-party infrastructure. Stop testing when sensitive information or unauthorised access is encountered.
11
Reveu does not currently claim to hold SOC 2, ISO 27001, PCI DSS, Cyber Essentials, or another independent security certification unless this is expressly stated in an updated notice.
Reveu also does not currently claim that the application has completed an independent penetration test.
Security documentation will be updated as the product, infrastructure, providers, testing, and assurance activities develop.