Skip to the page
VendorDue
InstallSoon

Security

How VendorDue protects your store

Last updated 6 October 2026

VendorDue keeps the record of what your vendors are owed. This page says how that record is protected, who can see what, and how to tell us about a problem.

  • Read-only in Shopify

    VendorDue can read orders, products and reports. It cannot change your store, your products or your customers.

  • Every store kept apart

    The database itself refuses any request for one store that reaches another store's records.

  • Sealed with your store's own key

    Contact details, payout addresses, messages and files are encrypted before they are saved.

  • Money never moves on its own

    A payment leaves your PayPal only when someone at your store presses Send now and proves it is them.

  • No customer identities

    Shopify sends customer names and addresses with each order. VendorDue drops them before saving anything.

  • Strong sign-in

    Passkeys, authenticator apps and emailed codes, with passwords checked against known leaks.

Found a security problem? Tell us at support@vendordue.com. Here is how we handle reports.
On this page

1. What VendorDue can reach in Shopify

VendorDue asks Shopify for three permissions, all read-only: orders, products and reports. It has no permission to change anything in your store, and it never asks for customer records.

Orders arrive with the customer's name, email, phone number and addresses. VendorDue keeps the order's contents, because a vendor's share is worked out from them, and drops who the customer is before anything is saved.

2. How each store is kept apart

Every table in VendorDue's database has row-level security turned on and forced. Each request names the one store it was made for, the database checks every row against it, and a request cannot read or change another store's rows, even if VendorDue's own code asked it to.

Who you are, which store you are in and what you may do are worked out on our servers on every request, never taken from your browser. Background work such as syncing runs as the system under the same rules.

3. Encryption

In transit. Every connection uses TLS, and vendordue.com tells browsers never to connect without it.

At rest. Each store has its own data key. Before they are saved, the fields below are encrypted with it using AES-256-GCM. The store's key is itself encrypted with a master key that lives outside the database, so a copy of the database or a backup on its own reveals none of them. The database provider also encrypts everything on disk.

  • Names and email addresses of your team, your vendors and their contacts

    Not encrypted, and why: Store names and vendor names as they appear on your products: VendorDue searches and groups by them, and they are already public on your storefront

  • Each vendor's PayPal or Venmo address, and your PayPal credentials

    Not encrypted, and why: Product titles and order numbers: searched and shown in every list

  • Messages, notes, reasons and files

    Not encrypted, and why: Amounts: VendorDue adds them up

  • Authenticator secrets

    Not encrypted, and why: Passkeys: only their public half is stored, which is safe to keep in the open

What this is not. This is not end-to-end encryption. VendorDue's servers open these fields while they do the work you ask for, such as emailing a payout, paying a vendor or showing a report.

4. Signing in

  • Inside Shopify Admin, VendorDue signs you in with Shopify's own session, so there is nothing more to remember.
  • On vendordue.com you can use a passkey, a password with a second step, or a code we email you. Authenticator apps work everywhere.
  • Every new password is checked against passwords leaked in other breaches. Only the first five characters of a one-way code made from it ever leave VendorDue.
  • Security lists every place you are signed in, with its device and rough location, and lets you end any of them.
  • Removing a lost sign-in method waits at least 24 hours, and you can cancel a recovery you did not ask for.

5. Actions that move money or remove records

  • Sending a payment or connecting PayPal needs a passkey or an authenticator code from the last five minutes. VendorDue never sends a payment on its own.
  • A vendor's new PayPal or Venmo address waits 48 hours before it is used. VendorDue emails the vendor, and a new PayPal connection is emailed to the store's owner. The link in either email stops the change.
  • Deleting a workspace, and starting over in a way that removes payment records, need a fresh proof of who you are. A deleted workspace can be recovered for 48 hours.

6. What the people who run VendorDue can see

To support stores and keep the service running, VendorDue's operator can see each store and its people by name and email, how each uses the app, and the store's sales, amounts owed and payments as totals per currency.

The operator's tools do not show individual orders, payout lines, what one vendor is owed or your conversations with vendors. Every time a person's details are opened there, it is recorded. Support sees only what you send it.

7. How the website defends itself

  • A content security policy with a fresh value on every page, so the only scripts that run are VendorDue's own and the few from Shopify and Cloudflare it names.
  • Pages outside Shopify Admin cannot be framed by another site.
  • Any change sent from another site is refused before it reaches the app.
  • Sign-in, support and every other change are limited per minute, and the public forms use Cloudflare Turnstile to tell people from bots.
  • Sign-in cookies are marked secure, HTTP-only and first-party, and are bound to vendordue.com.

8. Where VendorDue runs

The app runs on Cloudflare Workers, beside its Postgres database at Supabase in the United States (on Amazon Web Services). There are no servers of our own to patch. Secrets live in the hosting platform's encrypted settings, never in the code.

The database is backed up daily and each backup is kept for 7 days. The privacy policy says how we work with the providers we rely on.

9. When something goes wrong

We investigate every report and alert, contain the problem first, and fix its cause. If a breach affects a store's data we tell the store owner without undue delay, and within 72 hours of confirming it, with what happened, what it touched and what to do. The data processing addendum holds that promise in writing.

10. Taking your data and leaving

A store's admins can download a copy of the workspace from Settings, under Data and privacy. The file is sealed with the store's key while it waits, can be downloaded only by an admin of the store, and is deleted after 7 days. Deleting a workspace, or uninstalling VendorDue, erases everything the store held 48 hours later, including the key its data was encrypted with. Backups age out 7 days after that.

11. What we do not claim

  • VendorDue is not end-to-end encrypted.
  • We have not yet had an outside penetration test or a certification such as SOC 2. We will say so here when we do.
  • No system is perfectly secure. We tell you what we do so you can judge it.

12. Reporting a vulnerability

Email support@vendordue.com with what you found, the steps to reproduce it, and what it could let someone do. The same address is in /.well-known/security.txt. We reply within three working days.

While you research, please:

  • use only accounts and stores you own or have permission to test;
  • stop and tell us as soon as you reach anyone else's data, and do not keep or share it;
  • do not slow the service down or send spam;
  • give us 90 days to fix a problem before you talk about it publicly.

We will not pursue or support legal action against research done in good faith within these rules. VendorDue does not run a paid bug bounty yet, and we will thank you by name if you would like.

Questions about this page: support@vendordue.com.