How we protect your store and your customers
COD PRO handles customer phone numbers, emails and order details. Here is how we treat that data and who helps us deliver messages.
Access to your store
- COD PRO asks Shopify only for the permissions its features need. Optional permissions, such as email-marketing signals for the newsletter, are requested only when you turn that feature on.
- Your own tools connect with Agent API keys that you create, scope and revoke. Keys are stored hashed and every call is logged.
- One switch pauses all API access at any time.
Customer data
- We use customer contact details only to send the messages your store asked us to send.
- Activity logs never keep a shopper's raw phone number or email from a lookup.
- We honour Shopify's customer data and erasure requests.
Who delivers the messages
To deliver messages and run the service, we work with these providers:
- Twilio for WhatsApp, SMS and voice calls
- SendGrid for email
- Cloudflare for network protection and this website
- Groq for the in-app AI assistant
- Our hosting provider for the application servers
- Third-party address-search and mapping providers, to suggest addresses while a shopper types their street. Only the street text and country are sent, never name, phone or cart.
Report a security issue
If you find a vulnerability, email info@codpro.app with the subject "Security report". Please give us a reasonable time to fix it before sharing it publicly. We read every report.