Enscale Docs
Account

Security and privacy

How your store's data is kept separate, how customer consent is enforced, and what Enscale won't help you do.

What happens to your data and your customers' data, and the commitments behind it. Worth reading once before you go live — particularly the last section, which is the part that's yours rather than ours.

Your store's data is separate from everyone else's

Every Shopify store gets its own Enscale workspace, tied to your shop domain. Contacts, conversations, messages, automations, campaigns, reviews, AI agents, loyalty accounts and usage all live inside it.

Ownership is checked on Enscale's servers for every request, never assumed from what the request claims. There's no path for another store to reach your data by asking for it.

Who on your team can see what

RoleCan reach
OwnerEverything, including billing
AdminEverything except transferring ownership
AgentThe inbox and contacts only

Agents sign in with Enscale credentials and never need Shopify admin access. That's a security feature, not just a convenience — a support contractor should not have the ability to see your payouts or edit your products in order to answer a WhatsApp message.

Removing someone ends their access immediately. See Team and roles.

Before any outbound WhatsApp message — campaign or automation — Enscale checks that the contact opted in, hasn't opted out, has a valid number, and that the template is approved. Anyone failing a check is skipped and reported to you.

This isn't configurable, and that's deliberate. It's what protects your number.

Consent is stored as evidence, not a checkbox. Enscale records where each opt-in came from — popup, keyword reply, checkout, staff action, automation, AI conversation or import — and keeps the history of every change.

That record is what lets you answer "why did you message this person?" if Meta or a customer asks. See Contacts.

Opt-outs are automatic. STOP, UNSUBSCRIBE, CANCEL, END, QUIT and OPT OUT all take effect immediately and permanently. You never maintain a suppression list.

GDPR and customer data requests

Enscale implements Shopify's three mandatory privacy webhooks — customer data request, customer redact, and shop redact — and acts on them rather than acknowledging and discarding.

Every privacy operation is recorded in an audit log with a timestamp, so you can evidence what happened and when.

You can request a full export of your data at any time. See Data export and deletion.

Your channel connections

Channel connections use access tokens Meta issues when you authorise Enscale. Those tokens are never exposed to browsers or storefront code and never written to logs.

You can revoke them any time by disconnecting the channel — from Enscale, or directly from Meta.

Incoming events are signature-checked where the provider supports it, so Enscale won't act on a forged event claiming to be from Shopify or Meta.

AI agents

Agents are scoped to your workspace and answer from your own knowledge base and your Shopify data. They can't reach another store's anything.

Agents hand over to a person when they're unsure, when the customer asks for a human, when the topic is sensitive — payments, account changes, refunds, complaints — or when a limit you set is reached.

A customer can always reach a person

An AI agent should never leave someone stuck with no route to a human. If a customer asks for a person, that's honoured immediately. See AI handover.

Reviews: what Enscale won't do

Enscale will not help you hide negative reviews.

Moderation exists for spam, abuse, duplicates and policy violations. It is not a tool for suppressing low ratings — and the auto-publish settings are built so that holding a low rating for moderation means reviewing it, not burying it.

Showing only positive reviews while implying you show all of them is deceptive, and unlawful in many places. See Reviews.

It's also bad business. A wall of five stars reads as fake; a three-star review with a good reply under it proves the rest are real.

What Enscale stores, and why

Contacts, conversation history, consent evidence, Shopify references for context, media your customers sent, and usage records for billing.

Consent history is kept deliberately, because it's the evidence that you had permission to message someone — which is exactly what you need if it's ever questioned.

The part that's your responsibility

Enscale enforces a lot automatically. These five are yours:

  • Collect consent honestly. No pre-ticked boxes, no consent buried in fine print.
  • Categorise templates truthfully. Marketing content in a utility template damages your account rating — see Message templates.
  • Never import a list that didn't opt in. The single fastest way to lose your WhatsApp number.
  • Keep your team list current. Remove people when they leave.
  • Respect what customers actually signed up for. A back-in-stock signup is not permission for weekly promotions.

Next steps

On this page