Features How it works Mobile app Guide FAQ Contact

Konnectify on mobile

Orders, shipments and POS from your phone.

Get it on Google Play — coming soon Download on the App Store — coming soon

Coming soon to Android & iOS

Security & Incident Response Policy

Last updated: June 20, 2026

This page describes how Konnectify (operated by Goftech Solutions — “Konnectify”, “we”, “us”) secures personal data and responds to security incidents. It applies to all personal data we process, including the Shopify Protected Customer Data (shopper name, email, phone, address and order details) we process on behalf of merchants.


1. Purpose & scope

This policy defines how we detect, respond to, and report security incidents affecting the confidentiality, integrity or availability of personal data — with particular care for the customer (shopper) data we process for merchants via Shopify and WooCommerce. It covers our application, databases, integration credentials (encrypted Shopify/WooCommerce/WhatsApp/Meta/courier tokens), and supporting infrastructure.

A security incident is any actual or reasonably suspected event that compromises personal data or the systems that hold it — for example unauthorized access, credential or token leakage, data exfiltration, malware, account takeover, or accidental disclosure.

2. Roles & responsibilities

  • Incident Lead (Goftech Solutions security/engineering owner) — declares the incident, coordinates the response, and owns all external notifications.
  • Engineering on-call — investigates, contains, eradicates and recovers; preserves evidence and logs.
  • Support / Communications — notifies affected merchants and responds to their questions.

Suspected incidents can be reported to support@konnectify.net (monitored), and are escalated to the Incident Lead immediately.

3. Detection

Incidents are detected through application activity logging, error monitoring, infrastructure and hosting alerts, failed-authentication and anomaly signals, and inbound reports (from staff, merchants, Shopify, or security researchers). Any staff member who suspects an incident must report it to the Incident Lead without delay.

4. Response process

  • Identify & triage — confirm the event, classify its severity, and start an incident log with a timeline.
  • Contain — stop active harm: revoke and rotate affected credentials and API tokens, disable compromised accounts and sessions, block offending access, and isolate affected systems. Because integration tokens are encrypted and stored per store, containment can be scoped per merchant where possible.
  • Eradicate — remove the root cause (patch the vulnerability, remove malware, correct the misconfiguration).
  • Recover — restore service from a known-good state, verify data integrity, and increase monitoring on affected systems.
  • Preserve evidence — retain the logs and artifacts needed for investigation and any legal or regulatory obligations.

5. Severity classification

  • High — confirmed or likely exposure of protected customer data or integration credentials across one or more stores.
  • Medium — limited or contained exposure, or a vulnerability with credible risk but no confirmed data access.
  • Low — no personal data at risk (e.g. an isolated availability issue).

Severity drives escalation speed and the scope of notification.

6. Breach notification timelines

When an incident involves personal data, we notify the relevant parties promptly and without undue delay:

  • Shopify — for any breach involving Shopify customer data or our app’s access to it, we notify Shopify within 24 hours of confirming the incident, consistent with Shopify’s API Terms and Protected Customer Data requirements.
  • Affected merchants — we notify impacted merchants (the data controllers) without undue delay so they can meet their own obligations to their customers, including the nature of the incident, the data involved, and remediation steps.
  • Regulators & data subjects — where required by applicable law (e.g. the GDPR’s 72-hour regulator notification), we support merchants and notify as legally required.

All notifications include, to the extent known: what happened, when, the categories of data affected, the stores and merchants involved, the containment and remediation actions taken, and recommended next steps.

7. Post-incident review

Within a reasonable period after an incident is closed, the Incident Lead runs a post-incident review documenting the root cause, the response timeline, what worked, and corrective actions (technical fixes, and process or policy changes). Action items are tracked to completion, and this policy is updated where an incident reveals a gap.

8. Supporting safeguards

This policy operates alongside our standing controls:

  • Encryption in transit — all traffic is served over HTTPS/TLS.
  • Encryption at rest — integration tokens, device sessions and one-time codes are encrypted; the production database and its backups are encrypted at rest.
  • Access controls — multi-tenant isolation, role- and permission-based access with least privilege, and two-factor authentication on login.
  • Monitoring & logging — activity logging and error monitoring to detect and respond to issues.
  • Data-subject erasure — Shopify’s mandatory customers/data_request, customers/redact and shop/redact privacy webhooks are implemented for shopper and shop data erasure.

9. Review cadence

We review this policy at least annually, and after any material incident.


10. Contact

Security questions or incident reports: support@konnectify.net
Goftech Solutions — Islamabad, Pakistan.