Security

Thanks — your request has been sent. We acknowledge security reports within two business days and will be in touch at the email address you gave us.

Need help with security, privacy or compliance? Send us your request below and we’ll get back to you as soon as we can.

If you have found a potential security vulnerability in any Retail Force app, select Security issue — vulnerability report as the request type. We acknowledge these within two business days and will not pursue legal action against researchers acting in good faith.

Submit a request

All fields marked with an asterisk are required.

Helps us locate your account faster.
Attachments can’t be uploaded here. Mention that you have logs or screenshots and we’ll reply so you can send them by email.

By submitting, you agree we may contact you about this request. We handle what you send under our Privacy Policy. Please don’t include passwords, API tokens or customer payment details in this form.

1. Scope

This page covers the three applications published by SlashCart Inc. trading as Retail Force: RF—Retail Barcode Labels Print, OrderEditing.app & Upsell, and RetailForce: POS Time Clock In. It sits alongside our Privacy Policy, which is the authoritative statement of how we handle personal information, and our Terms of Service.

Where this page and the Privacy Policy differ, the Privacy Policy governs.

2. How our apps get access

Our apps do not hold your Shopify password and cannot log into your admin. Access works through Shopify’s OAuth permission model:

  • When you install an app, Shopify shows you the exact access scopes it requests, and you approve or decline them
  • The app receives a token limited to those scopes — nothing outside them is reachable, even by mistake
  • Every request we make is attributable to that token and subject to Shopify’s rate limits and audit trail
  • Uninstalling revokes the token immediately; the app loses all access at that moment

You can review what any installed app can access at any time under Settings → Apps and sales channels in your Shopify admin.

3. What each app can reach

Each app requests the minimum scopes needed to do its job.

App Data it accesses Personal data?
RF—Retail Barcode Labels Print Products, variants, SKUs, barcodes, inventory levels, prices, tags and product options No — product and inventory records only
OrderEditing.app & Upsell Orders, line items, totals, shipping and billing addresses, customer name and email, refund and transaction records Yes — buyer contact and address details
RetailForce: POS Time Clock In POS staff accounts, clock-in and clock-out records, shift schedules, assigned tasks, time-off requests, and staff-attributed sales for commission Yes — employee identity and working-time records

The barcode app is the narrowest of the three: it never needs order or customer data, and does not request it.

4. What we never receive

  • Payment card numbers, CVVs and bank details — handled by Shopify and its payment processors; they never pass through our systems
  • Your Shopify account password — authentication happens on Shopify’s side
  • Data outside your granted scopes — enforced by Shopify’s API, not by our own restraint
  • Data from other merchants — each store’s access token is isolated to that store

We do not sell merchant or buyer data, share it for advertising, or use your store data, your buyers’ data or your staff data to train machine-learning models.

5. Built for Shopify review

RF—Retail Barcode Labels Print and OrderEditing.app & Upsell both carry Shopify’s Built for Shopify designation. Shopify grants it only to apps that meet its published bar for security, performance, privacy handling and merchant experience, and it is reassessed rather than granted permanently.

RetailForce: POS Time Clock In launched in April 2026 and does not currently hold the Built for Shopify designation. It is subject to the same Shopify App Store review requirements as every listed app.

6. Deletion and GDPR webhooks

Every app on the Shopify App Store is required to implement Shopify’s mandatory compliance webhooks, and ours do:

Webhook What it means
customers/data_request A buyer asks you for the data held about them. We supply what we hold so you can respond.
customers/redact A buyer asks to be erased. We delete their personal data.
shop/redact Sent 48 hours after you uninstall. We delete your store’s data.

This means uninstalling is a real deletion path, not just a disconnection.

7. How long we keep data

Data Retention
Store and app data accessed through Shopify Deleted within 48 hours of uninstall, via shop/redact
Support correspondence Up to 24 months after the matter is closed
Billing and tax records As required by US federal and state law, generally 7 years
Aggregated, non-identifying usage statistics Indefinitely

Export anything you want to keep — generated barcode and SKU data, or time-clock records — before you uninstall.

8. Employee data in the POS app

RetailForce: POS Time Clock In records who worked, when, for how long, what tasks they completed and what time off they requested. That is employment data, and it carries obligations beyond ordinary customer data in most jurisdictions.

You are the data controller for your employees’ records. Before rolling the app out, tell your staff what is being recorded and why, confirm you have a lawful basis for recording it, and check your local employment, working-time and payroll rules. We process this data only on your instructions.

9. Your responsibilities

Most incidents involving apps begin on the merchant side. You can materially reduce your risk by:

  • Enabling two-step authentication on every Shopify staff account
  • Granting staff the minimum permissions their role needs, and removing access when people leave
  • Reviewing installed apps periodically and uninstalling anything unused
  • Checking the scopes requested whenever an app asks for new permissions
  • Verifying generated barcodes and SKUs before committing them to a production print run
  • Keeping your own export of any data you would not want to lose

10. Disclosure guidelines

When reporting a vulnerability through the form above, please include the affected app or URL, a description of the issue and its potential impact, steps to reproduce it, and how you would like to be credited if you would like credit.

While testing, please do not access, modify or delete data belonging to other merchants, run tests that degrade or disrupt the service, or use social engineering, phishing or physical attacks. Give us reasonable time to fix the issue before publishing anything about it.

We acknowledge reports within two business days and will keep you updated while we investigate. If your report concerns Shopify’s platform rather than our apps, it should go to Shopify’s own security programme.

11. Security contact

SlashCart Inc. — Retail Force is a DBA of SlashCart Inc.

131 Continental Drive, Suite 305
Newark, DE 19713
United States

Prefer email? support@retailforce.io with “Security” in the subject line.

Related: Privacy Policy · Terms of Service · Refund Policy