Compliance
PDPA and GDPR compliance are in scope. SOC2 Type 1 is listed as in progress with Q4 2026 target.
Merchant-facing security notes for a Shopify app that handles catalog, policy, and order lookup data.
PDPA and GDPR compliance are in scope. SOC2 Type 1 is listed as in progress with Q4 2026 target.
Visitor conversations and merchant data should not train public models. Final retention windows need legal review.
Annual penetration testing should be published here after vendor selection.
Singapore and Bangkok options are part of the trust story. Confirm infrastructure mapping before publication.