Kaspushop
Security
Version 2.0 · Effective 2026-10-05 · Contact contact@kaspushop.fr
Scope
Kaspushop is a Next.js website operated by KASB SYSTEMS. It communicates with the KASB SYSTEMS server, hosted with OVHcloud in Canada, which queries Shopify for the catalog and the cart. The customer account, payment and orders rely on Shopify.
Customer area sign-in
- Sign-in through the Shopify Customer Account API, as an OAuth 2.0 confidential client: the code exchange and token refresh happen server-side, with a secret that never leaves the server.
- State and nonce parameters checked on return from Shopify, against request forgery and replay.
- Tokens kept in httpOnly, Secure and SameSite=Lax cookies, never exposed to browser code.
Payment
Payments are entered on Shopify's checkout page, which complies with the PCI DSS standard; card details never pass through KASB SYSTEMS servers.
Exchanges with the server
Every request from the website to the KASB SYSTEMS server is signed (Ed25519) and valid for 30 seconds; the server rejects any unsigned or expired request. The private Shopify access token stays on the server, in a Docker secret.
Hosting and operations
- Encrypted HTTPS access to the website.
- Unprivileged production container: non-root user, read-only file system, exposed only locally behind the web server.
- Secrets loaded from the deployment environment, never present in the source code.
- Automatic blocking of malicious addresses and continuous service monitoring.
Incidents and reports
To report a vulnerability, an incident or to request deletion of your data: contact@kaspushop.fr.
Deletion requests are handled within the applicable legal timeframes; in the event of a personal data breach, KASB SYSTEMS notifies the CNIL within 72 hours and informs the data subjects where required by regulation.