Trust & Security

Enterprise-Grade Security & Compliance

Your customer data is protected by Shopify's infrastructure and Anchor's comprehensive compliance framework.

shield
GDPR Compliant
verified_user
CCPA Compliant
storefront
Shopify App Store Verified
accessibility
Accessible (WCAG)
policy

GDPR & CCPA Compliance

Full compliance with international data protection regulations. Your customers' privacy rights are built into every feature.

shieldGDPR Compliance

description

Data Request Handling

Customers can request a full export of their loyalty data at any time, in compliance with GDPR Article 15.

delete_sweep

Data Redaction (Right to be Forgotten)

Honor deletion requests with automated data redaction workflows triggered through Shopify webhooks.

person_off

Soft Delete & Anonymization

Customer data is anonymized rather than hard-deleted, preserving aggregate analytics while removing personal information.

cloud_done

Shopify Infrastructure Processing

All data processing happens within Shopify's infrastructure. No data leaves the Shopify ecosystem.

block

No Third-Party Data Sharing

Anchor never sells, shares, or transfers customer data to any third-party service or advertising platform.

fact_check

Consent Management

Built-in consent mechanisms ensure customers are informed about how their loyalty data is collected and used.

verified_userCCPA Compliance

California Privacy Rights

Full support for California consumer privacy rights including the right to know, delete, and opt-out.

Data Portability

Customers can request their data in a portable, machine-readable format (CSV and JSON).

Opt-Out Mechanisms

Customers can opt out of data collection with clear, accessible controls.

gavel

Quebec Compliance: Points Don't Expire

In Quebec, loyalty points cannot legally expire. Anchor supports configurable per-region expiration rules, allowing you to disable point expiration for Quebec customers while maintaining expiration policies for other regions.

lock

Data Security

Built on Shopify's world-class infrastructure with zero external dependencies. Your data never leaves the Shopify ecosystem.

database

Shopify Infrastructure Only

All loyalty data is stored within Shopify's secure infrastructure. No external databases or third-party servers.

lock

SSL/TLS Encryption

All data in transit is encrypted with industry-standard SSL/TLS protocols.

key

Shopify App Bridge Auth

Secure authentication through Shopify App Bridge ensures only authorized merchants access their data.

visibility_off

No Client-Side Sensitive Data

Sensitive data is never stored or exposed in the browser. All operations are server-side.

receipt_long

Webhook Event Logging

Complete audit trails through webhook event logging for every data operation.

dns

No External Dependencies

Zero reliance on external APIs or services for core functionality, minimizing attack surface.

accessibility_new

Accessibility

Every customer deserves a seamless loyalty experience. Anchor is built with accessibility at its core.

record_voice_over

Screen Reader Support

Full ARIA labeling and semantic HTML in the loyalty widget for complete screen reader compatibility.

keyboard

Keyboard Navigation

All interactive elements are fully navigable via keyboard with logical tab order.

format_textdirection_r_to_l

RTL Language Support

Complete right-to-left layout support for Arabic, Hebrew, and other RTL languages.

verified

WCAG 2.1 AA Compliance

Meets Web Content Accessibility Guidelines 2.1 Level AA standards across all widget components.

contrast

High Contrast Compatible

Widget adapts to high contrast mode and respects user's system accessibility preferences.

center_focus_strong

Focus Indicators

Clear, visible focus indicators on all interactive elements for users navigating without a mouse.

admin_panel_settings

Admin Controls

Granular controls to manage exactly who earns points, what products qualify, and a complete audit trail of every action.

mail

Staff Email Exclusion

Automatically exclude staff email addresses from earning points, preventing test orders from inflating loyalty data.

label_off

Customer Tag Exclusion

Exclude wholesale accounts, staff accounts, or any customer group by tag from earning or redeeming points.

inventory_2

Product & Collection Exclusion

Control exactly which products and collections earn points. Exclude sale items, gift cards, or specific categories.

history

Audit Log

Complete audit log for all admin actions including configuration changes, manual point adjustments, and tier modifications.

assignment

GDPR Data Request Log

Dedicated log tracking all GDPR data requests, their status, and resolution timestamps.

filter_list

Webhook Event Log

Comprehensive webhook event log with filtering by event type, date range, and pagination for easy review.

download

Data Export & Portability

Your data belongs to you. Export everything at any time in the format you need.

table_view

CSV Export

Export customer loyalty data and transaction history in CSV format for spreadsheets and analysis.

data_object

JSON Export

Machine-readable JSON exports for integration with other systems and data processing pipelines.

swap_horiz

Full Data Portability

Complete data portability ensures merchants can export all loyalty program data at any time.

dynamic_feed

Bulk Operations

Support for bulk data operations including mass exports, imports, and point adjustments.

verified_user

Your customers' trust is our priority

Security and compliance aren't afterthoughts at Anchor. They're built into every feature, every line of code, and every decision we make.