Safety and privacy
Claude never changes your shop behind your back. This page explains, in plain words, how you stay in control and what happens to your data. The section at the end is for your IT person or developer.
Nothing changes without your yes
Every change works in three steps:
- Preview. Claude shows you what it wants to change: the old text and the new text, old and new price, and any warnings.
- You approve. Claude waits. Only when you reply "yes" does it save.
- Save. The change is saved the same way as when an employee clicks Save in the back office.
A preview is valid for 30 minutes and works once. If someone changes the same product in the back office in the meantime, Claude has to show you a new preview.
Reading (audits, searches, reports) changes nothing and needs no approval.
The TellMyShop standard: how Claude talks about changes
Before every change Claude shows what will change, tells you the risk and how to undo it, and asks for your approval. For prices and promotions you get a short risk card.
The module reminds Claude of this standard on every connection and with every preview. The higher the risk, the more Claude says:
| Risk | When | What Claude says |
|---|---|---|
| Low | descriptions, meta, alt texts, CMS pages, new products | before and after, one question, no "just in case" warnings |
| Medium | page addresses and redirects, categories and category assignments; any change with warnings; a low-risk change on more than 20 items | the same plus 1–2 sentences: what customers or Google will see and how to undo it |
| High | Sales (prices, promotions, discount codes, stock, shipping), appearance, modules, service mode; a medium-risk change on more than 20 items | a short risk card (up to 5 lines): what changes and where, who it affects, what could go wrong and how likely that is, how to undo it and what can't be undone, and a good time for the change if it matters |
With more than 20 items Claude first shows 2–3 samples. When it isn't sure something will work, it says so and suggests trying it on one item. Only a clear "yes" to a specific preview counts as approval; "ok" without context, a question, "maybe" or no answer is not approval. After saving, Claude checks the result, reports it briefly with numbers (for example "28 of 30, 2 skipped because…") and tells you how to undo it. If something went differently from the preview, it says so plainly and doesn't retry without your approval.
For low-risk changes Claude deliberately adds no warnings: too many warnings teach people to click "yes" without reading.
Your shop rules for Claude. In the Settings: security, alerts, limits card you can write your own rules, one per line, for example "We address customers informally", "Never use the word cheap", "Descriptions up to 600 characters" (up to 1000 characters in total). Claude receives them on every connection. They never switch off the preview or your approval before saving.
Undoing changes
- Ask "What did you change yesterday?" and Claude shows the list. The Change history and undo card in the module shows it too.
- Ask "Undo that change" and Claude restores the earlier value, again after a preview.
- New products, categories and pages Claude created can be removed the same way.
- Files (theme, modules, shop files): a backup is made before every change, and any backup can be brought back from the File backups card (paid version only).
- Database changes in service mode: the changed rows are copied first, so the change can be undone.
- Page addresses: Claude changes the address back and checks that the old one redirects.
A few things can't be undone from the change history, and Claude says so in the preview: changes to product photo files, installing, updating or uninstalling a module, and structural database changes in service mode. Theme file changes are brought back from the File backups card instead.
You choose what Claude can touch
- After installation Claude can only read.
- Sales (prices, promotions, shipping) is off until you turn it on.
- Technical work (look of the shop, modules, service mode) needs a separate service connector that works only from approved addresses and expires after 30 days. Service mode switches itself off after 1 to 24 hours.
- Claude works as its own employee with only the permissions you give it. The shop's log shows everything it did.
- There is a limit on how much Claude can do per hour: with separate limits for actions and for changes. You can change it in the Settings: security, alerts, limits card.
- Big jobs are checked before they start. Before work on more than about 20 items, Claude checks whether it fits your hourly limits and tells you in one sentence: it fits, or it doesn't. If it doesn't, it suggests a way before starting: doing it in stages, raising the limit in the panel for the duration of the work, or a cheaper way. Every preview and every change shows what is left this hour, and a batch of changes never stops halfway.
You hear about every change of the rules
- An email every time a safety setting is loosened: read-only mode off, Sales or a technical area on, service mode on, customer data access on, a service connector created, IP lists cleared, alerts off.
- A daily summary by email on days when something happened: how many times Claude connected, what it changed, and any alerts.
- An alert on unusual activity: a burst of changes in a short time, or an address blocked after 20 failed attempts to connect.
- A check of the module's own files. If someone changes or adds a file in the module, you get an alert.
- An emergency key. If a technical change leaves the shop showing a blank page, you open the rescue address, enter the key and the module brings back the files it changed. It works even when the shop doesn't.
Alerts go to the shop's email address unless you set another one.
Extra safety for prices
- A price can't be set to 0.
- A price change of more than 30% needs your extra approval.
- A sale above 90% off needs your extra approval; above 50% you get a warning.
- New discount codes start switched off. You check them before customers can use them.
Your customers' data
Designed to help you meet the requirements of GDPR, UK GDPR, CCPA/CPRA and LGPD. Your shop stays the data controller and decides how customer data is used, and this is not a certificate of compliance.
Built to PrestaShop's technical standards for modules: safe queries, escaping, file protection, complete uninstall.
By default Claude doesn't see your customers' personal data at all. You can change that in the Customer data (GDPR) card, in one of three levels:
- Off (default). Claude doesn't see customers, addresses, orders or messages. Sales reports show products and amounts, without names.
- Pseudonymised. Claude sees orders, customer messages and statistics, but names are shortened to initials, emails, phone numbers and addresses are replaced with an alias such as "Klient-3f9a1c", and IP addresses are cut short. The same customer keeps the same alias for one day; the next day the alias is different. Claude can say "this customer ordered 3 times" without knowing who it is. It can't change customer data. Customer service needs at least this level.
- Full access (temporary). For 1, 4, 8 or 24 hours, then it goes back to the previous level on its own. You type the purpose when you turn it on, e.g. "complaint about order 1234", and you get an email. Use it only when a task really needs it.
What else protects your customers:
- The module finds personal data on its own. It recognises every table holding emails, names, phone numbers, addresses, birth dates or IP addresses, including tables from other vendors' modules (reviews, newsletters, loyalty programmes). You don't have to point at anything. The Customer data (GDPR) card shows how many tables it found.
- Files Claude won't open. Files with passwords and keys, customer files (
upload/,download/), server logs, database dumps and backups,.gitand the connector's own files are always blocked. When Claude reads logs or messages, emails, phone numbers and IP addresses are masked. - Encryption. The change history entries with customer data and all file backups are stored encrypted. The key lives in a file outside the database, so a leak of the database alone doesn't expose them.
- The PrestaShop GDPR module. If you use PrestaShop's official GDPR module (psgdpr), a customer's request to erase or export their data also covers TellMyShop's history.
TellMyShop gives you tools to protect personal data. The legal side stays with you as the shop owner: legal basis, privacy policy, record of processing, a data processing agreement with Anthropic and transfers outside the EEA. The module shows suggested texts for your privacy policy and record of processing; have them checked by a lawyer.
More safeguards: the change history and the PrestaShop log mask customer data, staff names, IP addresses and keys in what Claude sees. The change history list always masks customer data, whatever access level you chose. Full access needs a licence, read-only mode off and a purpose of at least 10 characters, and reminds you of the data processing agreement with Anthropic. Uninstalling keeps the history by default. The Customer data (GDPR) card has a Download audit log (CSV) button: the audit log shows who turned on full data access, service mode, blocks and the licence, and when, and it can't be cleared from the panel. The change history is deleted after 180 days by default.
Service mode and your customers' data. In service mode (block 4 Modules and block 5 Service mode) a developer working with Claude can change your shop's code, so the protection of your customers' data then depends on that person. Choose someone you trust and switch these blocks on only for the time the work takes. Turning on block 4 or 5 asks for the purpose of the work (at least 10 characters); the purpose, who turned it on and when go to the audit log, and you get an email.
Where your data goes
- The module runs on your own server.
- When Claude reads something, it goes from your shop to your Claude account at Anthropic. Anthropic's terms apply to your conversations.
- TellMyShop doesn't receive your products, orders or customers. The licence check sends only your licence key, shop domain, a random installation ID and version numbers (module, PrestaShop, PHP). It sends no usage counts.
Text in your shop is not an instruction
Product descriptions, pages or customer messages can contain any text, including text that looks like a command. Claude treats it as content, not as instructions. And nothing is saved without your approval anyway.
Keep your connector address secret
The connector address contains a secret key, like a password. Don't share it. If it leaks, generate a new one in the module settings; the old one stops working at once.
Technical details
Authentication. Static tokens, no OAuth in 2.6.0 (Roadmap). Token in the URL (?token=) or Authorization: Bearer. Only the SHA-256 hash and a prefix are stored; the full token is shown once; a new token revokes the old one immediately. A URL token can land in web server and proxy logs: prefer the header where the client supports it and rotate the token if it leaks. The panel recommends replacing the daily token every six months.
Two connectors. Daily token: core, block 1 Content & SEO, block 2 Commerce. Service token: additionally blocks 3–5, accepted only from IPs on its own allowlist (mandatory; default Anthropic range 160.79.104.0/21) and only while one of blocks 3–5 is active; expires after SERVICE_TOKEN_TTL days (default 30, 7–90). Test token: 2 minutes.
Endpoint protections (src/Endpoint.php, in this order):
| # | Protection | Value |
|---|---|---|
| 1 | Connector switch | Off after install until the merchant turns it on (503) |
| 2 | Transport | HTTPS only (403) |
| 3 | IP lockout | 20 failed authentications from one IP within 10 minutes; lifts when the window passes; alert to the owner (429) |
| 4 | IP allowlist | Optional, both connectors; empty = no restriction |
| 4a | Service connector | Own mandatory allowlist + at least one active block 3–5 |
| 5 | Origin | A request with an Origin header must come from https://claude.ai, https://claude.com, https://chatgpt.com or https://chat.openai.com; requests without Origin pass |
| 6 | Token | Daily, service or test |
| 7 | Rate limits | Hourly limits on calls, writes and file writes, adjustable in the Settings: security, alerts, limits card. A write with a batch of up to 50 items counts as one write; the write limit is checked before saving. Remaining limits are shown in every preview and write and in ps_get_shop_info; ps_check_capacity checks a planned job first |
| 8 | Block check | Repeated on every call |
| 9 | Permissions | Per back-office tab and action of the connector employee (ExecutionContext::requirePermissions); SuperAdmin refused |
Client IP: proxy headers (CF-Connecting-IP, X-Forwarded-For) are used only when "Shop behind a proxy / Cloudflare" is on and the direct peer is on the trusted proxy list.
Writes. change_token = HMAC of tool, arguments and a hash of the "before" state; 30 minutes, single use; execution is blocked if the data changed after the preview. Saves go through ObjectModel (ObjectWriter): per-field validation, only changed fields, actionObject…Update* hooks, PrestaShop log entry with the connector employee ID, change history. Details: Specification §5.
Files. Theme: Smarty whitelist and test compile, JSON check, warnings for new scripts and external domains, parent theme read-only. Modules and shop files (Files\Zone): relative paths only, realpath() inside the zone, text extensions only; always denied: app/config/parameters.*, config/settings*.inc.php, .env*, *.key|pem|p12|crt|sql|sql.gz|dump|bak, .git, .svn, var/logs, upload, download, the module's private directory and the module itself. PHP files: syntax check with token_get_all(TOKEN_PARSE) before writing; no code execution tool. Every write is preceded by a backup; backups kept 90 days, at least the last 5 per file.
SQL (block 5). ps_db_query: SELECT/SHOW/DESCRIBE/EXPLAIN in a READ ONLY transaction, max 200 rows, emails and phones masked. ps_db_execute: one statement; UPDATE/DELETE on one table back up matching rows first (max 1000) and roll back if more rows change than declared; INSERT is undone by deleting the row; DDL has no backup and is flagged in the preview. Always blocked: employees, sessions, profiles and access, configuration (use ps_config, secrets masked), webservice and API clients, connector tables. Personal-data tables only at customer data level pseudo (masked) or full. The filter is pattern-based and protects against mistakes, not against deliberate circumvention; service mode is full trust, which is why it is time-limited, IP-bound and on a separate token.
Customer data (src/Privacy/PersonalData.php). Levels off / pseudo / full (CUSTOMER_DATA); full only for 1/4/8/24 h with a stated purpose and an explicit acknowledgement, then back to the previous level. Detection: fixed list of PrestaShop and common module tables (customer, address, orders, cart, messages, newsletter, psgdpr…) plus any table with a column whose name matches email, first/last name, phone, address, postcode, IP, birth date, tax ID or secret patterns, read from information_schema; business tables (contact, store, supplier, manufacturer, warehouse, carrier) excluded. Masking at level pseudo: email, phone, address and ID numbers → alias Klient- + 6 hex characters (HMAC-SHA256 with a daily key derived from var/tellmyshop/keys/pseudonym.key: the same value gives the same alias within one day and a different one the next day); name → initials plus the alias; IPv4 → first two octets, IPv6 and integer IPs hidden; birth date → year; secrets → ***. Free text (logs, messages, files): emails are shortened to j***@g***.com, phones, IPs, tokens and Authorization headers masked. ps_list_changes masks customer data in every entry regardless of CUSTOMER_DATA (column values as above, other values as free text). Not "GDPR compliant" as a claim: pseudonymised data is still personal data (GDPR recital 26) and the shop stays the controller.
Encryption (src/Security/Crypto.php). libsodium secretbox (XSalsa20-Poly1305), 32-byte key in var/tellmyshop/keys/history.key outside the database. Encrypted: change history of customer-data objects and all file backups. Losing the key = encrypted changes can no longer be undone. A full server compromise (files and database) also exposes the key; encryption protects against a database-only leak. Back up the key file together with your server backup and store the copy separately.
psgdpr. Hooks actionDeleteGDPRCustomer (erases the customer's data from the encrypted history) and actionExportGDPRData (lists connector operations that touched the customer, without values).
Owner alerts (src/Security/Alerts.php). Email plus a log entry with status ALERT for: read-only off, customer data pseudo/full, block 2–5 on, service mode on, service token generated, IP lists cleared, alerts off, write burst, IP lockout, module file integrity breach. Same event at most once per 15 minutes (panel events always). Daily summary once per 24 h. Integrity: integrity.json (SHA-256 of every file) compared with disk; changed, deleted and added PHP files detected; checked on every panel visit and at most every 6 h by the connector.
Rescue key (src/Security/RescueKey.php). Shown once; only its SHA-256 is stored. A script is copied to the shop root under a random name, because PrestaShop blocks direct PHP calls in modules/. It restores files changed by the connector and switches service mode off; it doesn't undo database changes. Removed on uninstall.
Retention. Connection log 30 days (7–180); change history 180 days (30–730); file backups 90 days with at least 5 per file.
Not needed: PrestaShop Account, Eventbus. Outbound calls: the licence server (https://tellmyshop.pl/api/v1), the shop's own pages (HttpProbe, URL checks), module ZIP and image URLs that Claude passes on the merchant's request.
Checklist for IT
- Dedicated inactive employee and profile, not SuperAdmin (the "Create Claude's account" button does this).
- Read-only mode on until the merchant has tested reads.
- Sales off unless needed; service token generated only for technical work; emergency key generated first and stored outside the shop.
- Customer data access off unless a task needs it; full access only for a stated purpose.
- IP allowlists reviewed; proxy setting correct if the shop is behind Cloudflare.
- Alert email address checked.
- Connector address stored as a secret; header auth where possible.
- Database backups scheduled, independent of TellMyShop.
-
ps_check_shop_healthrun before larger changes.
PrestaShop is a registered trademark of PrestaShop SA. Claude is a trademark of Anthropic. TellMyShop is not affiliated with either.
Last updated: 2026-10-04