Effective date: 07 August 2026
This page describes how Bloom Labs protects client confidentiality and data when we work inside your store and systems. It is a trust statement; binding terms for any engagement are in your services agreement and any data processing terms.
1. Our role
When engaged, we may receive access to your Shopify store, code, apps, analytics and the personal information of your customers. In relation to your customers' personal information, you are the controlling party and we act on your instructions as part of delivering the work. We access data only to the extent needed to perform the services.
2. Confidentiality
We keep your non-public information confidential and use it only to perform the engagement, including your code, data, strategy, pricing, roadmaps and customer information. Confidentiality obligations continue after the engagement ends. We are happy to sign your NDA.
3. Access controls
- Least-privilege access: we request only the permissions and collaborator access required, and prefer scoped or staff accounts over owner credentials.
- We do not store admin passwords in plain text and use a reputable password manager and, where available, multi-factor authentication.
- Access is granted per person and revoked when the work ends or a team member rolls off.
4. Safe engineering practices
- We build on unpublished or duplicate themes or development environments and never make untested changes directly to a live store.
- Changes go through review and testing (UAT) before deploy, with higher-risk deploys scheduled for safe, off-peak windows.
- We keep backups and versioned copies before significant changes so work can be rolled back.
5. Third-party subprocessors
We use reputable tools to run our business and deliver work (e.g. Shopify, project management, communication and code tools) and take reasonable steps to ensure they maintain appropriate security. A current list is available on request.
6. Data handling and retention
We hold client data only for as long as needed for the engagement or as required by law, and return or securely destroy it on request at the end of the engagement, subject to legal retention obligations.
7. Incident response
If we become aware of a security incident affecting your data, we will notify you without undue delay and cooperate to contain and remediate it, consistent with your agreement and applicable law (including the Notifiable Data Breaches scheme under the Privacy Act, where relevant).