Trust & safety
You're connecting a real store to an automated tool. Here is exactly how we protect your data, your credentials, and your storefront — and what we will never do.
Storenode is an independent SaaS app that writes product drafts into your Shopify store. That means we hold credentials to a system you depend on, so we treat security as a core part of the product, not an afterthought. This page describes the practices we follow today. We describe what we actually do, and we do not claim certifications we do not hold.
Store credentials at rest. The access token used to connect your Shopify store is encrypted at rest using AES-256-GCM, an authenticated encryption standard. The token is used only to create and update drafts in your store at your direction, and you can disconnect your store at any time.
Data in transit. Traffic to and from the Service is encrypted in transit using TLS, so data moving between your browser, our application, and our providers is protected on the wire.
Sign-in and account management are handled by a dedicated third-party authentication provider. We do not store your password ourselves. This gives you a hardened, continually-maintained identity layer and keeps your login credentials out of our own systems.
The website and application are hosted on an established cloud platform, with uploaded files stored in managed object storage and application data in a managed PostgreSQL database. We rely on reputable, professionally-operated infrastructure providers and benefit from their physical and network security controls.
We apply least-privilege principles: systems and the people who operate them are granted only the access they need to do their job, and access to your data is limited accordingly. The token we hold for your store is scoped to the operations the Service actually performs.
The most important safety property of Storenode is structural: the Service only ever creates drafts, and never automatically publishes to your store. Nothing goes live until you review it and choose to publish. A tool that could push to a live store without a human checkpoint is a tool that can break a store — so we designed that capability out.
Payments and billing are handled by a PCI-compliant third-party payment processor. Storenode does not store full payment card numbers. We receive only the limited billing metadata needed to manage your subscription and usage credits.
To generate drafts, the product content you submit is processed by established third-party AI providers. We send only the content needed to perform the requested task, and we do not use your content to train our own models. See our Privacy Policy for more on how this data is handled.
We want to be straight with you: this page reflects the security practices we follow today, not a formal compliance certification. Storenode does not currently claim SOC 2, ISO 27001, or PCI certification of its own. Where regulated handling is required — for example, payment card data — we rely on specialist providers (such as a PCI-compliant payment processor) rather than handling it ourselves. We will update this page as our practices and any certifications evolve.
If you believe you have found a security vulnerability in Storenode, we want to hear from you. Please report it privately to support@storenode.ai with enough detail for us to reproduce and investigate it. Please give us a reasonable opportunity to address the issue before any public disclosure, and avoid accessing or modifying data that is not yours while testing. We appreciate good-faith research and will work with you on any valid report.
For any security or privacy question, contact us at support@storenode.ai. You can also read our Privacy Policy, Terms of Service, and Data Processing Addendum.