Home/Security
Enterprise Cloud Infrastructure

Security Architecture & Data Protection

How Woonic secures your Shopify catalog data, theme files, and configurations using Amazon Web Services (AWS) S3 encryption, zero-trust token handshakes, and strict data retention controls.

1. Encryption at Rest & in Transit

All store snapshot files, product data payloads, and Liquid templates captured by Woonic are subjected to bank-grade encryption protocols:

  • Encryption at Rest (AES-256): All backup artifacts written to Amazon S3 buckets are encrypted using Server-Side Encryption with Amazon S3 managed keys (SSE-S3) utilizing 256-bit Advanced Encryption Standard.
  • Encryption in Transit (TLS 1.3): All network traffic between Shopify's API endpoints, Woonic's application servers, and AWS cloud storage is strictly enforced over HTTPS utilizing Transport Layer Security (TLS) 1.3 with forward secrecy.

2. Cloud Storage Infrastructure & Durability

Backup vaults are hosted on Amazon Web Services (AWS) S3 infrastructure, which is designed to provide 99.999999999% (11 9s) of data durability over a given year. AWS S3 redundantly stores your data across multiple geographic Availability Zones to protect against infrastructure degradation, facility outages, and hardware failure.

3. Zero-Trust Access & Scoped OAuth Permissions

Woonic communicates with your store exclusively using Shopify's official OAuth handshake. We request strictly minimal, granular read/write scopes necessary to execute backups and restores (e.g. read_themes, write_themes, read_products). We never store long-lived Admin API secret tokens, customer credit card information, or checkout payment credentials.

4. Data Retention & Automatic Purging

We store backup snapshots only for as long as necessary to fulfill our service commitment:

  • Active Subscriptions: Daily snapshot archives are maintained for 1 year (or extended custom periods on Plus plans).
  • App Uninstallation: When you uninstall Woonic from your Shopify store, Shopify triggers a mandatory app/uninstalled webhook. Upon receipt, Woonic revokes API connections, schedules your stored S3 archives for deletion, and permanently purges all customer-associated snapshot data within 30 business days.

5. Authorized Sub-Processors

Woonic utilizes a limited set of vetted cloud service providers to operate its backup and staging pipelines:

Sub-ProcessorService PurposeData Location
Amazon Web Services (AWS)Encrypted cloud storage (S3) & compute hostingUnited States (US East)
Shopify Inc.E-commerce platform host & GraphQL API providerCanada / Global Edge CDN
Resend / CrispTransactional email alerts & live chat supportUnited States / EU

6. Security Inquiries & Incident Reporting

If you have security questions, compliance requirements, or wish to report a vulnerability, please contact our infrastructure security team at info.woonic@gmail.com.