1. Scope
This policy covers the TaskFlow AI platform (taskflow-ai.com), its integrations (including the "Allchat TaskFlow WhatsApp" Shopify app and WhatsApp Business Platform connections) and all personal data we process on behalf of our customers ("merchants"), including Shopify protected customer data. It is owned by AllChat J4U Ltd. and reviewed at least once a year.
2. How we protect data
- Data minimisation: integrations request read-only scopes and store only the fields needed to send order, shipping and cart messages.
- Encryption in transit (TLS/HTTPS only) and at rest (managed database encryption); third-party access tokens and app secrets are additionally encrypted with AES-256-GCM.
- Tenant isolation enforced in the database with row-level security; every request is scoped to a single workspace.
- Least-privilege staff access; administrative access to customer workspaces is restricted to authorised staff and audited.
- Access logging: views, exports, links and redactions of merchants' store customer data are recorded in an access log retained for 400 days.
- Every incoming webhook is signature-verified (HMAC); invalid requests are rejected.
- Uptime and database health are monitored continuously with automatic alerts to the on-call owner.
3. What counts as a security incident
Any event that compromises, or is reasonably suspected to compromise, the confidentiality, integrity or availability of personal data or of the platform — for example unauthorised access to data or credentials, leaked tokens, data sent to the wrong recipient, malware, or a prolonged outage.
4. Response process
- Report & detect. Incidents are reported by monitoring alerts, staff, customers or researchers to privacy@taskflow-ai.com. Every report is acknowledged and logged.
- Triage (within 24 hours). The incident owner (the company's security lead) assesses scope, affected merchants and data, and severity.
- Contain. Revoke or rotate affected credentials and tokens, disable affected integrations or accounts, block malicious access, and preserve logs as evidence.
- Eradicate & recover. Fix the root cause, restore from backups where needed, and verify normal operation.
- Notify. Affected merchants are notified without undue delay and no later than 72 hours after we confirm an incident involving their customers' personal data, with what happened, what data was affected and what we are doing. Where the incident involves Shopify data we also notify Shopify as required by the Shopify Partner Program Agreement. Regulators and data subjects are notified as required by law, including the Israeli Privacy Protection (Data Security) Regulations, 5777-2017 and, where applicable, the GDPR.
- Review. Within two weeks we document the timeline, root cause and corrective actions, and track them to completion.
5. Records and testing
Incident records are kept for at least 24 months. The process is exercised at least once a year and after any significant change to the platform.
6. Contact
Security and privacy reports: privacy@taskflow-ai.com. Please include a description, the affected account or URL, and how to reproduce the issue.
