Skip to content
Install on Shopify
Legal/TRUST CENTER

Trust Center

Everything you need to trust us. In one place.

How Arbyn keeps your store and your customers’ data safe, plus every document you or a bigger buyer might ask for, gathered in one place so you never have to chase us for it.

24 subprocessors
SOC 2 + ISO 27001 infrastructure
GDPR + CCPA ready
Zero-retention LLMs
01 · COMPLIANCE STATUS

The current picture, nothing inflated.

What Arbyn actually does with your data, split into two honest groups: the controls we run ourselves today, and the certifications we inherit from our infrastructure or still have on the roadmap. Nothing inflated.

What Arbyn does today
ACTIVE

Shopify GDPR webhooks

All three mandatory Shopify webhooks implemented, customers/data_request, customers/redact (30 days), and shop/redact (48 hours after uninstall). Everything purged.

Shopify App Store compliant
ACTIVE

Minimal Shopify API scopes

Arbyn requests only the Shopify API access scopes it actually needs, no over-permissioning. Full scope list shown in the install modal before you confirm.

Reviewed every release
ACTIVE

GDPR

Controller and processor model documented. SCCs in place for international transfers. DSAR support with 30-day SLA.

DPA available · See details →
ACTIVE

CCPA / CPRA

Right-to-know, right-to-delete, and opt-out flows implemented. California consumer rights honored across all Arbyn surfaces.

Privacy notice current
NOT APPLICABLE

HIPAA

Arbyn doesn't process PHI by default. Postmark (our transactional email subprocessor) is HIPAA-compliant if your use case requires it, contact us.

BAA on request
INHERITED

PCI-DSS

Arbyn never touches card data. All billing flows through Shopify (Level 1 PCI-DSS certified). We're out of scope by design.

Via Shopify Billing
ACTIVE

Zero-retention LLMs

Signed zero-retention agreements with every LLM provider. Inference inputs are never stored, never logged for training, never reused.

ACTIVE

DSAR / Data subject requests

Access, deletion, and portability requests handled within 30 days. Self-serve flow for store owners; email flow for end customers.

Certifications: our roadmap, and the infrastructure we run on

Arbyn is not certified on its own yet. The platform runs on Google Cloud, which holds a current SOC 2 Type 2 report, a public SOC 3 report and an accredited ISO/IEC 27001 certificate. Those are Google’s, they are real, and they cover the infrastructure layer only, not Arbyn’s own application. Google’s SOC 2 report is confidential to their customers and we cannot redistribute it; request the pack below and we will send what we are permitted to share. Arbyn’s own SOC 2 and ISO 27001 are on the roadmap, not claimed as done.

ROADMAP

SOC 2 Type II

Arbyn is not SOC 2 certified yet, and has not begun its own audit. The platform runs on Google Cloud, whose SOC 2 Type 2 covers the infrastructure layer; Google’s public SOC 3 report is the version that can be shared freely. Our own SOC 2 is on the roadmap.

Runs on SOC 2 infrastructure today
ROADMAP

ISO 27001

Google Cloud (our infrastructure provider) holds an accredited ISO/IEC 27001 certificate today, so we inherit the infrastructure-layer technical controls. Arbyn's own certification is planned, no date committed.

Inherited via Google Cloud
03 · DOCUMENTS & REPORTS

Policies, agreements, and reports. Public or on request.

Customer-facing policies are public. Infrastructure audit reports and subprocessor agreements ship on request under NDA, one form with your name, company, and reason gets you the package within one business day.

Public documents
Customer DPAPUBLIC

Our standard Data Processing Agreement, ready to countersign for your security review.

View →
Privacy policyPUBLIC

What we collect, why, how long we keep it, and who we share it with.

View →
Subprocessor listPUBLIC

Every third party we use. 24 subprocessors · 30-day change notices

View →
Terms of servicePUBLIC

The MSA between Arbyn and you, acceptable use, liability, and termination.

View →
Infrastructure compliance · Google Cloud (our hosting provider) · available
SOC 3PUBLIC

Google Cloud's SOC 2 results prepared for a general audience. No NDA required. This is the report we can point anyone to.

View document →
ISO/IEC 27001PUBLIC

Google Cloud's accredited certification to the ISO/IEC 27001 Information Security Management standard, audited by an independent third party. Current certificate published by Google

View document →
SOC 2 Type 2ON REQUEST

Google's independent audit of Security, Confidentiality and Availability controls at the infrastructure layer. Google Confidential, we cannot redistribute it. Ask us and we will tell you how to obtain it directly from Google, and send everything we are permitted to share.

Cloud Data Processing AddendumPUBLIC

Google's DPA covering personal data processed on Google Cloud infrastructure, including its published CCPA/CPRA privacy mapping. Current version published by Google

View document →
Subprocessor DPAs · available on request
LLM provider DPAsON REQUEST

Zero-retention agreements with our AI model providers, details available under NDA.

Postmark BAA (HIPAA)ON REQUEST

If your use case requires HIPAA, our transactional email subprocessor offers a BAA. We'll set it up.

All other subprocessor DPAsON REQUEST

Cloudflare, Shopify, AWS, Sentry, we'll share each one as needed for your security review.

04 · SECURITY CONTACTS

How to reach the right person for the right thing.

Each request goes to a real human, and every one is logged so nothing gets lost in an inbox. Pick the right one and you'll get a faster, more useful reply.

VULNERABILITY DISCLOSURE
Found something?
Responsible disclosure. 48-hour acknowledgement, public credit if you want it.
DATA SUBJECT REQUESTS
Access, deletion, portability
DSARs handled within 30 days per GDPR/CCPA. Identity verification required.
SUBPROCESSOR CHANGES
30-day notice subscription
Get told before any subprocessor changes, 30 days ahead. No marketing, only notices.
INCIDENT REPORTING
Something looks wrong?
Suspected breach, abuse, or operational issue. Critical incidents acknowledged within 1 hour.

Need anything that isn't here? Just ask.

We answer security review questions in plain English, fast. Your request reaches the founders, not a ticketing system, and it is logged so it cannot get lost.

Or book a call