Enscale Docs
Account

Security and privacy

How Enscale isolates your data, handles consent and GDPR, protects credentials, and treats reviews honestly.

This page covers how Enscale handles your data and your customers' data, and the commitments behind that.

Your data is isolated

Every Shopify store gets its own Enscale workspace, keyed to your shop domain. Contacts, conversations, messages, workflows, campaigns, reviews, AI agents, loyalty accounts, and usage records all live inside it.

Data access is scoped to a single workspace and verified on the backend for every request. A client cannot reach another store's data by asking for it — ownership is checked server-side, never inferred from what the request claims.

Access control

RoleAccess
OwnerEverything, including billing.
AdminEverything except ownership transfer.
AgentInbox and contacts only.

Agents sign in with Enscale credentials and don't need Shopify admin access. That's a security feature, not just a convenience — support contractors shouldn't have store admin rights to answer a message. See Team and roles.

Removing a teammate ends their access immediately.

WhatsApp outbound requires explicit opt-in, and Enscale enforces it rather than trusting you to remember.

Before any outbound WhatsApp message — campaign or automation — Enscale checks that the contact opted in, hasn't opted out, has a valid number, and that the template is approved where one is required. Contacts failing any check are skipped and reported.

Consent is stored as evidence, not a flag. Enscale records where each opt-in came from — popup, keyword reply, checkout, staff action, workflow, AI conversation, or import — and keeps a history of changes.

That record is what lets you answer "why did you message this person?" if Meta or a customer asks. See Contacts.

Opt-outs are handled automatically. A customer replying STOP, UNSUBSCRIBE, CANCEL, END, QUIT, or OPT OUT is opted out immediately and excluded from all outbound messaging. You never maintain a suppression list.

GDPR and data rights

Enscale implements Shopify's three mandatory privacy webhooks — customer data request, customer redact, and shop redact — and actually acts on them rather than acknowledging and discarding.

Every privacy operation is recorded in an audit log with a timestamp.

You can request a full data export at any time. Export links expire deliberately: an archive of your entire customer conversation history shouldn't sit on a permanent URL.

See Data export and deletion.

Credentials

Channel connections use tokens issued by Meta when you authorise Enscale. Those tokens are never exposed to browsers or storefront code, never written to logs, and can be revoked by disconnecting the channel — from Enscale or from Meta directly.

Incoming webhooks are signature-validated where the provider supports it, so Enscale won't act on a forged event.

AI safety

AI agents are scoped to your workspace and answer from your knowledge base and your Shopify data.

Agents hand over to a human when confidence is low, when the customer asks for a person, when the topic is sensitive — payments, account changes, refunds, complaints — or when a configured limit is reached.

An AI agent should never leave a customer stuck with no route to a person. If a customer asks for a human, that request is honoured. See Handover.

Review authenticity

Enscale will not help you hide negative reviews.

Moderation exists for spam, abuse, duplicate submissions, and policy violations. It is not a tool for suppressing low ratings, and the auto-publish settings are deliberately built so that holding low ratings for moderation means reviewing them, not burying them.

Displaying only positive reviews while implying you show all of them is deceptive, and in many jurisdictions unlawful. See Reviews.

Data minimisation

Enscale stores what's needed to run the product, support you, and meet legal obligations — contacts, conversation history, consent evidence, Shopify references for context, media customers sent, and usage records for billing.

Consent history is retained deliberately, because it's the evidence that you had permission to message someone.

Your responsibilities

Enscale enforces a lot automatically, but some things are yours:

  • Collect consent honestly. Don't pre-tick boxes or bury consent in fine print.
  • Categorise templates truthfully. Marketing content in a utility template damages your account rating. See Message templates.
  • Don't import lists that never opted in. The fastest way to get a WhatsApp number restricted.
  • Keep your team list current. Remove people when they leave.
  • Respect what customers signed up for. A back-in-stock signup isn't consent for weekly promotions.

Next steps

On this page