Skip to content

Security and data practices

Last updated: October 8, 2026

What this page is

This page describes controls that are implemented in AdParity. It does not say the service has passed an audit or earned a security certification.

Access and credentials

The public site uses HTTPS. Shopify and Google refresh credentials are written only by the server, in Firestore collections the browser cannot read. A signed-in request must come from the same site and carry the session header. Workspace membership, not a store id supplied by the browser, decides which store you can see. Owners manage connections. The Admin SDK bypasses Firestore rules, so server routes check membership themselves.

Scanning

Production browser checks run on an Azure Container Apps worker. Vercel calls that worker with a server-only secret. The worker accepts a workspace and store id for a connected Shopify store. It rejects an arbitrary storefront URL. Logs are written without access tokens or raw tracking payloads. AdParity does not store payment card numbers.

Secrets

API secrets, the worker secret, and the Firebase service account stay in environment storage on Vercel and Azure. They are not prefixed for the browser and they are not committed in the application repository as live values.

Checks

Pass and fail results come from deterministic comparisons. The product stores the evidence needed to explain a finding. It does not store storefront cookies or a full browser profile.

Contact

A public security contact address is not configured. Do not send secrets to the alert sender address.