Security and data practices
Last updated: October 8, 2026
What this page is
This page describes controls that are implemented in AdParity. It does not say the service has passed an audit or earned a security certification.
Access and credentials
The public site uses HTTPS. Shopify and Google refresh credentials are written only by the server, in Firestore collections the browser cannot read. A signed-in request must come from the same site and carry the session header. Workspace membership, not a store id supplied by the browser, decides which store you can see. Owners manage connections. The Admin SDK bypasses Firestore rules, so server routes check membership themselves.
Scanning
Production browser checks run on an Azure Container Apps worker. Vercel calls that worker with a server-only secret. The worker accepts a workspace and store id for a connected Shopify store. It rejects an arbitrary storefront URL. Logs are written without access tokens or raw tracking payloads. AdParity does not store payment card numbers.
Secrets
API secrets, the worker secret, and the Firebase service account stay in environment storage on Vercel and Azure. They are not prefixed for the browser and they are not committed in the application repository as live values.
Checks
Pass and fail results come from deterministic comparisons. The product stores the evidence needed to explain a finding. It does not store storefront cookies or a full browser profile.
Contact
A public security contact address is not configured. Do not send secrets to the alert sender address.