The New Standard for Shopify Loyalty
Transform your customers into a high-octane affiliate force.
Transform your customers into a high-octane affiliate force.
We use cookies to enhance your experience and analyze our traffic.
Reward Me is a Shopify-embedded application that enables merchants to run affiliate and rewards programs. It is distributed through the Shopify App Store and operates as a server-side application hosted on a dedicated server.
The application follows a clean, layered architecture (Domain → Application → Infrastructure) with strict separation of concerns. All business logic is isolated from framework code.
API keys carry explicit, scoped permissions (e.g., affiliates:read, orders:write). Every protected endpoint declares its required permissions, enforced server-side on every request.
All inbound Shopify webhooks are verified using HMAC-SHA256 against the raw request body before any processing occurs. Unverified payloads are rejected immediately.
All incoming request payloads are validated against strict DTOs before reaching business logic. Responses are serialised to expose only explicitly declared fields, preventing accidental data leakage.
All external communication is encrypted using HTTPS with TLS certificates issued by a trusted CA, with automatic renewal. No sensitive data is transmitted over unencrypted channels.
The MySQL database uses tablespace encryption for all application tables, including transaction logs. Data files on disk are encrypted independently of the application.
Sensitive entity fields are additionally encrypted at the application layer using strong symmetric encryption before being written to the database, providing defence-in-depth independent of database-level controls.
| Webhook | Purpose |
|---|---|
customers/data_request |
Respond to a customer's request for their personal data |
customers/redact |
Delete a customer's personal data upon request |
shop/redact |
Delete all shop data following app uninstallation |
The app requests only the Shopify API permission scopes necessary for its stated functionality. No excess scopes are declared.
This document provides a summary of the security controls in place for Reward Me. Detailed implementation information is available on request under NDA.
Last Updated: February 11, 2026
Welcome to RewardMe ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Shopify application and related services.
We collect information that you provide directly to us, including:
We use the information we collect to:
We may share your information in the following circumstances:
We do not sell your personal information to third parties.
We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. This includes encryption, secure servers, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
We retain your information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. When you uninstall RewardMe, we will delete or anonymize your data within 30 days, except where we are required to retain it for legal purposes.
Depending on your location, you may have the following rights:
To exercise these rights, please contact us at privacy@aisbjo.com.
We use cookies and similar tracking technologies to collect information about your browsing activities. You can control cookies through your browser settings. Please note that disabling cookies may affect the functionality of our services.
Our services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: general@aisbjo.com
Website: aisbjo.com
By using RewardMe, you acknowledge that you have read and understood this Privacy Policy.