Mcfly Ads
Security
Last updated: July 28, 2026. Practices that match our least-privilege data diet — not a guarantee against every threat.
Controls we run
- HTTPS for the marketing site and the hosted Shopify app.
- Shopify OAuth for install and Admin API access — App URL is the hosted app, never mcflyads.com.
- HMAC verification on compliance and other Shopify webhooks; invalid signatures are rejected.
- Least-privilege scopes —
read_orders, minimalread_customers(opaque id +numberOfOrders), andread_all_ordersonly when Partner-approved for history depth. No name, email, phone, or address fields. - Data diet — OrderFact / CohortFact store opaque order ids and amounts/dates, not name/email/phone/address CRM.
- Deletion —
customers/redact,shop/redact, and uninstall cascade delete merchant data; ComplianceDataExport packages purge after 60 days on a schedule. - Secrets — API tokens and OAuth secrets live in host env / secret stores, not in the public site repo.
Infrastructure
App: Fly.io + managed Postgres. Site: Cloudflare Pages. See Privacy · Processors.
Report a vulnerability
Email mcflyadsmmm@gmail.com with “Security” in the subject. Do not publicly disclose until we have a chance to respond.
Privacy · Terms · DPA (draft)