Last updated: June 2026
Least privilege, scoped service keys
Appolar follows the principle of least privilege. It only requests the access it actually needs to read your catalog and place orders through checkout, and nothing more. Wherever a credential is involved, Appolar uses scoped service keys issued through each platform's official mechanism. It never asks for, sees, or stores your raw passwords.
Apple and Google credentials are scoped and revocable
To submit your app, Appolar uses scoped, app-specific access to your Apple Developer and Google Play accounts, not your full login. You grant it, and you can revoke it at any time, immediately, without breaking the apps already published under your name. The submission keys cover the build pipeline and nothing else.
Data in transit and at rest
Traffic between the builder, Appolar's services, and Shopify is encrypted in transit using TLS. The configuration and catalog data Appolar holds to run your app is encrypted at rest. Access to that data is limited to what the platform needs to compile and serve your app.
You own your developer accounts
Your Apple Developer and Google Play accounts remain entirely yours. Appolar submits on your behalf but never takes ownership. If you stop using Appolar, the access is revoked and your published apps keep running on your accounts. Nothing about your app is held hostage on someone else's developer account.
Checkout and payments stay with Shopify
When a shopper checks out, the app hands off to Shopify's native checkout. Appolar never processes, stores, or even sees card data. PCI compliance stays with Shopify, exactly as it does for your web store. Apple Pay, Google Pay, and Shop Pay live inside Shopify's checkout sheet, not inside any Appolar-controlled screen, so the payment surface is the one your shoppers already trust.
Responsible disclosure
If you find a vulnerability or a security concern in Appolar, please report it privately rather than disclosing it publicly. Email support@appolar.com with the details and steps to reproduce. Reports go straight to the developer and are taken seriously.
A small, deliberate surface area
Appolar is built and run by one developer, and the system is kept intentionally simple. Fewer moving parts, fewer third-party services in the data path, and fewer permissions requested mean fewer ways for something to go wrong. Where this approach trades scale for clarity, that trade is on purpose.
Contact
Security questions, key concerns, or disclosure reports all go to support@appolar.com. For how data is collected and retained, see the privacy policy.