Enterprise-Grade Security & Compliance
Your customer data is protected by Shopify's infrastructure and Anchor's comprehensive compliance framework.
GDPR & CCPA Compliance
Full compliance with international data protection regulations. Your customers' privacy rights are built into every feature.
shieldGDPR Compliance
Data Request Handling
Customers can request a full export of their loyalty data at any time, in compliance with GDPR Article 15.
Data Redaction (Right to be Forgotten)
Honor deletion requests with automated data redaction workflows triggered through Shopify webhooks.
Soft Delete & Anonymization
Customer data is anonymized rather than hard-deleted, preserving aggregate analytics while removing personal information.
Shopify Infrastructure Processing
All data processing happens within Shopify's infrastructure. No data leaves the Shopify ecosystem.
No Third-Party Data Sharing
Anchor never sells, shares, or transfers customer data to any third-party service or advertising platform.
Consent Management
Built-in consent mechanisms ensure customers are informed about how their loyalty data is collected and used.
verified_userCCPA Compliance
California Privacy Rights
Full support for California consumer privacy rights including the right to know, delete, and opt-out.
Data Portability
Customers can request their data in a portable, machine-readable format (CSV and JSON).
Opt-Out Mechanisms
Customers can opt out of data collection with clear, accessible controls.
Quebec Compliance: Points Don't Expire
In Quebec, loyalty points cannot legally expire. Anchor supports configurable per-region expiration rules, allowing you to disable point expiration for Quebec customers while maintaining expiration policies for other regions.
Data Security
Built on Shopify's world-class infrastructure with zero external dependencies. Your data never leaves the Shopify ecosystem.
Shopify Infrastructure Only
All loyalty data is stored within Shopify's secure infrastructure. No external databases or third-party servers.
SSL/TLS Encryption
All data in transit is encrypted with industry-standard SSL/TLS protocols.
Shopify App Bridge Auth
Secure authentication through Shopify App Bridge ensures only authorized merchants access their data.
No Client-Side Sensitive Data
Sensitive data is never stored or exposed in the browser. All operations are server-side.
Webhook Event Logging
Complete audit trails through webhook event logging for every data operation.
No External Dependencies
Zero reliance on external APIs or services for core functionality, minimizing attack surface.
Accessibility
Every customer deserves a seamless loyalty experience. Anchor is built with accessibility at its core.
Screen Reader Support
Full ARIA labeling and semantic HTML in the loyalty widget for complete screen reader compatibility.
Keyboard Navigation
All interactive elements are fully navigable via keyboard with logical tab order.
RTL Language Support
Complete right-to-left layout support for Arabic, Hebrew, and other RTL languages.
WCAG 2.1 AA Compliance
Meets Web Content Accessibility Guidelines 2.1 Level AA standards across all widget components.
High Contrast Compatible
Widget adapts to high contrast mode and respects user's system accessibility preferences.
Focus Indicators
Clear, visible focus indicators on all interactive elements for users navigating without a mouse.
Admin Controls
Granular controls to manage exactly who earns points, what products qualify, and a complete audit trail of every action.
Staff Email Exclusion
Automatically exclude staff email addresses from earning points, preventing test orders from inflating loyalty data.
Customer Tag Exclusion
Exclude wholesale accounts, staff accounts, or any customer group by tag from earning or redeeming points.
Product & Collection Exclusion
Control exactly which products and collections earn points. Exclude sale items, gift cards, or specific categories.
Audit Log
Complete audit log for all admin actions including configuration changes, manual point adjustments, and tier modifications.
GDPR Data Request Log
Dedicated log tracking all GDPR data requests, their status, and resolution timestamps.
Webhook Event Log
Comprehensive webhook event log with filtering by event type, date range, and pagination for easy review.
Data Export & Portability
Your data belongs to you. Export everything at any time in the format you need.
CSV Export
Export customer loyalty data and transaction history in CSV format for spreadsheets and analysis.
JSON Export
Machine-readable JSON exports for integration with other systems and data processing pipelines.
Full Data Portability
Complete data portability ensures merchants can export all loyalty program data at any time.
Bulk Operations
Support for bulk data operations including mass exports, imports, and point adjustments.
Your customers' trust is our priority
Security and compliance aren't afterthoughts at Anchor. They're built into every feature, every line of code, and every decision we make.