Security at Reveu

Protecting merchant and customer information.

Reveu applies practical security controls across its public website, Shopify application, data handling, storefront integrations, and privacy workflows.

Core principles

A practical, layered approach to security.

Reveu combines request verification, restricted data access, validation, privacy controls, and operational safeguards to reduce unnecessary risk.

01

Limit access

Public-facing services are designed to expose only the actions required for a feature to work. Administrative reads, updates, and deletions are restricted.

02

Verify requests

Requests originating from Shopify integrations are checked before trusted actions are performed.

03

Validate inputs

Public forms, application settings, imported content, URLs, and request data are validated before they are accepted or processed.

04

Collect less

Reveu aims to collect only the information required to operate a feature, provide support, or meet legal and privacy obligations.

Security overview

Reveu’s current security controls are designed around the information and integrations used by the public website and Shopify application.

Restricted public data access

Website form submissions cannot be publicly listed, read, edited, or deleted.

Shopify request verification

Shopify webhooks and app-proxy requests are checked before processing.

Input validation

Form fields, settings, media URLs, and imported data are validated.

Privacy cleanup

Uninstall and privacy workflows are connected to merchant and review-data cleanup processes.

01

Current scope

This page describes the security approach currently applied to:

  • The public website at reveu.me
  • The early-access waitlist
  • The public contact form
  • The Reveu Shopify application
  • Shopify webhooks and app-proxy requests
  • Review collection and moderation workflows
  • Review-request email processing
  • Review imports and product matching
  • Storefront widgets and theme integrations
  • Uninstall and privacy-request processing

Reveu is still preparing for launch. Security controls, documentation, service providers, and operational procedures may continue to develop as testing progresses.

02

Public website security

The public website collects a limited amount of information through the early-access waitlist and contact form.

Current website protections include:

  • HTTPS-encrypted website connections
  • Strict field and data-type validation for public submissions
  • Maximum lengths for names, email addresses, URLs, and messages
  • Controlled enquiry types rather than unrestricted categories
  • Required privacy acknowledgement for contact enquiries
  • Create-only Firestore rules for public form submissions
  • Public reading, listing, editing, and deleting of submissions disabled
  • Lightweight protection against automated and spam submissions
  • No public file uploads through the contact form

Visitors should not submit passwords, authentication codes, payment-card information, or unnecessary sensitive personal information through the website.

03

Shopify integration security

Reveu uses Shopify application interfaces, webhooks, app proxies, theme app extensions, products, orders, customers, and fulfilment events to provide its merchant features.

Security measures applied to Shopify integrations include:

  • Validation of the Shopify store associated with application requests
  • Signature verification for Shopify app-proxy requests
  • Verification of webhook requests before trusted processing
  • Error handling that does not incorrectly mark failed webhook processing as successful
  • Separation of merchant-specific data and application configuration
  • Removal of merchant data through uninstall and privacy workflows where required
  • Validation of settings before they are stored or applied
Shopify dependency

Reveu depends on Shopify services and interfaces. Shopify outages, API changes, access restrictions, or platform security events may affect Reveu even where Reveu’s own systems are operating normally.

04

Data protection and access

Reveu aims to limit access to merchant, customer, review, and website-submission data to the systems and people that require it for legitimate operational purposes.

Current protections include:

  • Restricted public access to website form submissions
  • Validation of uploaded or referenced review media URLs
  • Limited collection of website contact information
  • Separation of waitlist and contact-form records
  • Retention limits for public website submissions
  • Review-media cleanup connected to deletion workflows
  • Protection of production credentials from public frontend code
  • Server-side processing for trusted application actions

Reveu’s handling of personal information is explained further in the Privacy Policy.

05

Privacy and deletion workflows

Reveu includes workflows intended to support Shopify privacy requirements and merchant-data cleanup.

These workflows include:

  • Customer-data privacy request processing
  • Shop-data deletion processing
  • Application uninstall cleanup
  • Review and review-media deletion handling
  • Removal of application configuration where required
  • Failure reporting when cleanup cannot be completed

Privacy-processing errors are not intentionally hidden or silently treated as successful. This supports investigation and retry handling where required.

06

Application security controls

Reveu applies validation and defensive controls across review, email, import, storefront, and merchant-setting workflows.

Review submissions

Submission data, verification status, review-request tokens, customer media, and moderation settings are checked before processing.

Email automation

Review-request delays are validated, provider failures are surfaced, and production sending is not treated as successful when no email provider is available.

Review imports

Imported content is checked and matched using controlled product identifiers such as handles, product IDs, and SKUs.

Storefront output

Theme widgets use controlled settings and validation to reduce unsafe or unexpected storefront output.

Media handling

Review media references are validated before trusted processing or deletion actions are performed.

Background processing

Queue jobs and scheduled review requests use validated identifiers and explicit failure handling.

07

Infrastructure and service providers

Reveu uses third-party infrastructure and technology services to operate the website and application.

These may include:

  • Shopify
  • Google Firebase and Cloud Firestore
  • Website and application hosting providers
  • Email-delivery providers
  • Domain, DNS, and network providers

Reveu evaluates providers based on the service required, available security controls, data-processing needs, and operational suitability.

No internet or cloud service can guarantee complete protection against every security event. Third-party outages or incidents may also affect Reveu services.

08

Merchant security responsibilities

Security is shared between Reveu, Shopify, service providers, and each merchant.

Merchants are responsible for:

  • Protecting Shopify account credentials
  • Using multi-factor authentication where available
  • Restricting staff access to authorised users
  • Reviewing installed Shopify applications
  • Keeping themes and connected services maintained
  • Checking imported review data before publication
  • Moderating customer-submitted review content
  • Removing access for staff who no longer require it
  • Reporting suspected misuse or unauthorised access

Reveu will never require a merchant to send a Shopify password or authentication code through the public contact form.

09

Security incidents

If Reveu becomes aware of a suspected security incident, the response may include:

  • Investigating the affected systems and information
  • Restricting or suspending affected access
  • Preserving relevant technical records
  • Correcting the underlying vulnerability
  • Reviewing whether information was accessed or altered
  • Working with relevant service providers
  • Notifying affected parties where appropriate
  • Meeting applicable legal or regulatory obligations

The exact response will depend on the nature, severity, scope, and likely impact of the incident.

10

Report a security concern

Security researchers, merchants, and website visitors may report a suspected vulnerability or security issue directly to Reveu.

Include:

  • A clear description of the issue
  • The affected page, feature, or endpoint
  • Steps that reproduce the issue
  • The potential impact
  • Relevant screenshots or non-sensitive logs
  • A safe way to contact you
Security reports hello@reveu.me
Report a security issue
Please test responsibly

Do not access, alter, download, disclose, or destroy data belonging to another person. Do not disrupt the website, application, Shopify stores, or third-party infrastructure. Stop testing when sensitive information or unauthorised access is encountered.