Need help with security, privacy or compliance? Send us your request below and we’ll get back to you as soon as we can.
If you have found a potential security vulnerability in any Retail Force app, select Security issue — vulnerability report as the request type. We acknowledge these within two business days and will not pursue legal action against researchers acting in good faith.
Security details
1. Scope
This page covers the three applications published by SlashCart Inc. trading as Retail Force: RF—Retail Barcode Labels Print, OrderEditing.app & Upsell, and RetailForce: POS Time Clock In. It sits alongside our Privacy Policy, which is the authoritative statement of how we handle personal information, and our Terms of Service.
Where this page and the Privacy Policy differ, the Privacy Policy governs.
2. How our apps get access
Our apps do not hold your Shopify password and cannot log into your admin. Access works through Shopify’s OAuth permission model:
- When you install an app, Shopify shows you the exact access scopes it requests, and you approve or decline them
- The app receives a token limited to those scopes — nothing outside them is reachable, even by mistake
- Every request we make is attributable to that token and subject to Shopify’s rate limits and audit trail
- Uninstalling revokes the token immediately; the app loses all access at that moment
You can review what any installed app can access at any time under Settings → Apps and sales channels in your Shopify admin.
3. What each app can reach
Each app requests the minimum scopes needed to do its job.
| App | Data it accesses | Personal data? |
|---|---|---|
| RF—Retail Barcode Labels Print | Products, variants, SKUs, barcodes, inventory levels, prices, tags and product options | No — product and inventory records only |
| OrderEditing.app & Upsell | Orders, line items, totals, shipping and billing addresses, customer name and email, refund and transaction records | Yes — buyer contact and address details |
| RetailForce: POS Time Clock In | POS staff accounts, clock-in and clock-out records, shift schedules, assigned tasks, time-off requests, and staff-attributed sales for commission | Yes — employee identity and working-time records |
The barcode app is the narrowest of the three: it never needs order or customer data, and does not request it.
4. What we never receive
- Payment card numbers, CVVs and bank details — handled by Shopify and its payment processors; they never pass through our systems
- Your Shopify account password — authentication happens on Shopify’s side
- Data outside your granted scopes — enforced by Shopify’s API, not by our own restraint
- Data from other merchants — each store’s access token is isolated to that store
We do not sell merchant or buyer data, share it for advertising, or use your store data, your buyers’ data or your staff data to train machine-learning models.
5. Built for Shopify review
RF—Retail Barcode Labels Print and OrderEditing.app & Upsell both carry Shopify’s Built for Shopify designation. Shopify grants it only to apps that meet its published bar for security, performance, privacy handling and merchant experience, and it is reassessed rather than granted permanently.
RetailForce: POS Time Clock In launched in April 2026 and does not currently hold the Built for Shopify designation. It is subject to the same Shopify App Store review requirements as every listed app.
6. Deletion and GDPR webhooks
Every app on the Shopify App Store is required to implement Shopify’s mandatory compliance webhooks, and ours do:
| Webhook | What it means |
|---|---|
customers/data_request |
A buyer asks you for the data held about them. We supply what we hold so you can respond. |
customers/redact |
A buyer asks to be erased. We delete their personal data. |
shop/redact |
Sent 48 hours after you uninstall. We delete your store’s data. |
This means uninstalling is a real deletion path, not just a disconnection.
7. How long we keep data
| Data | Retention |
|---|---|
| Store and app data accessed through Shopify | Deleted within 48 hours of uninstall, via shop/redact
|
| Support correspondence | Up to 24 months after the matter is closed |
| Billing and tax records | As required by US federal and state law, generally 7 years |
| Aggregated, non-identifying usage statistics | Indefinitely |
Export anything you want to keep — generated barcode and SKU data, or time-clock records — before you uninstall.
8. Employee data in the POS app
RetailForce: POS Time Clock In records who worked, when, for how long, what tasks they completed and what time off they requested. That is employment data, and it carries obligations beyond ordinary customer data in most jurisdictions.
You are the data controller for your employees’ records. Before rolling the app out, tell your staff what is being recorded and why, confirm you have a lawful basis for recording it, and check your local employment, working-time and payroll rules. We process this data only on your instructions.
9. Your responsibilities
Most incidents involving apps begin on the merchant side. You can materially reduce your risk by:
- Enabling two-step authentication on every Shopify staff account
- Granting staff the minimum permissions their role needs, and removing access when people leave
- Reviewing installed apps periodically and uninstalling anything unused
- Checking the scopes requested whenever an app asks for new permissions
- Verifying generated barcodes and SKUs before committing them to a production print run
- Keeping your own export of any data you would not want to lose
10. Disclosure guidelines
When reporting a vulnerability through the form above, please include the affected app or URL, a description of the issue and its potential impact, steps to reproduce it, and how you would like to be credited if you would like credit.
While testing, please do not access, modify or delete data belonging to other merchants, run tests that degrade or disrupt the service, or use social engineering, phishing or physical attacks. Give us reasonable time to fix the issue before publishing anything about it.
We acknowledge reports within two business days and will keep you updated while we investigate. If your report concerns Shopify’s platform rather than our apps, it should go to Shopify’s own security programme.
11. Security contact
SlashCart Inc. — Retail Force is a DBA of SlashCart Inc.
131 Continental Drive, Suite 305
Newark, DE 19713
United States
Prefer email? support@retailforce.io with “Security” in the subject line.
Related: Privacy Policy · Terms of Service · Refund Policy