For Daily Use
How it works Bot filtering Pricing FAQ Add to Shopify

Legal

Security Incident Response Policy

Last updated: April 2026

What counts as a security incident

  • Unauthorised access to merchant or customer data
  • Exposure of Shopify access tokens, API keys, or encrypted credentials
  • Breach of the application database (draws, entries, winner data, contact details)
  • Compromise of a third-party integration credential (e.g. Klaviyo API key)
  • Any vulnerability actively exploited in production

Our response commitments

Within 24 hours of discovery:

  • Contain the incident (revoke compromised tokens, invalidate sessions, take affected systems offline if necessary)
  • Begin internal investigation to determine scope and affected parties

Within 48 hours:

  • Reset all affected credentials (Shopify access tokens, Klaviyo API keys, database passwords)
  • Apply any required patches or configuration changes
  • Confirm containment

Within 72 hours of discovery:

  • Notify all affected merchants by email with: what happened and when, what data was affected (or potentially affected), what we have done to contain it, what merchants should do (if anything is required on their end), and a contact address for questions

Data we hold

The following data could be affected in a security incident:

  • Customer names, email addresses, phone numbers — belonging to merchant customers who entered a draw or giveaway
  • Draw and giveaway configuration — belonging to merchants
  • Winner status and Shopify draft order references — belonging to merchants
  • Shopify store access tokens — issued by Shopify, used to operate the embedded app
  • Klaviyo API keys — encrypted at rest using AES-256-GCM

We do not store payment card data. All payments are handled by Shopify.

Reporting a vulnerability

If you have discovered a security vulnerability in For Daily Use, please report it to privacy@fordailyuse.com.

Include a description of the vulnerability, steps to reproduce, and the potential impact. We will acknowledge your report within 48 hours and keep you informed of our progress.

Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.

Contact

  • Security and privacy: privacy@fordailyuse.com
  • General support: help@fordailyuse.com
For Daily Use

Drop management for Shopify.

How it works Bot filtering Pricing FAQ Privacy Security Support

© 2026 For Daily Use. All rights reserved.

We collect name, email, phone, and IP address from draw entrants on behalf of Shopify merchants. Entrant data is deleted 48 hours after a merchant uninstalls, and entry IP addresses are anonymised 90 days after a draw ends. See our Privacy Policy for full details.