Security
Effective date: 31 July 2026
Store Huddle is operated by Slurvo FZ-LLC and is designed to protect merchant, staff, and Shopify customer information using administrative, technical, and organizational controls.
Security Controls
Store Huddle encrypts data in transit using HTTPS, and every session is authenticated through Shopify’s OAuth flow, so access to a workspace is tied to a verified Shopify session rather than a separate Store Huddle password.
Each merchant’s workspace is logically isolated from every other merchant’s data. Access within a workspace is governed by role-based permissions, so a user only sees the rooms, channels, and information their role allows. Files and uploads are only reachable through authenticated, time-limited links rather than public URLs, and inbound requests from Shopify, including webhooks, are cryptographically verified before we act on them.
Production infrastructure runs on established cloud providers with their own independent security and compliance programs. Access to production systems is restricted to authorized personnel on a need-to-know basis, and encryption and access controls are applied wherever the underlying infrastructure supports them. We don’t publish further implementation detail here, since doing so mainly helps attackers, not merchants; if you have a specific security question as part of a vendor review, email us and we’ll work through it directly.
Incident Response
We investigate suspected security incidents and take reasonable steps to contain, remediate, and document confirmed incidents. Where legally required, affected merchants or authorities will be notified without undue delay.
Vulnerability Reporting
To report a suspected vulnerability, email support@storehuddle.com with the subject:
Security report
Include reproduction steps, affected URLs or features, and the potential impact. Do not access another user’s information, disrupt production, use social engineering, or publicly disclose an unresolved vulnerability.
We will acknowledge good-faith security reports and investigate them as reasonably practicable. Submission of a report does not create entitlement to payment or participation in a bug-bounty program.
Contact
Slurvo FZ-LLC
SFFO0050, Compass Building, Al Shohada Road,
Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates
Email: support@storehuddle.com