TellMyShop security

Every change waits for your “yes”.

The chat can prepare as many changes as it likes. Only what you see in the preview and approve within 30 minutes reaches your store. Try it below.

Card status: waiting for your “yes”
Sora rattan lantern, Google titleLampiarnia demo store
old version: Lampiarnia - lanterns and garden lighting
new version: Sora rattan lantern, hand-woven, for the patio
Approval for this change onlystill valid for 30:00
risklow

1. Access

It reads first. You turn on the rest yourself, for a set time

Pick a level and see what the chat can do and where the limit is. The switch is checked at the moment you approve, and the owner gets an email whenever wider access is turned on.

Read onlyFree and Pro, always
The chat can
Free reads ready-made reports: SEO, 404 errors, store health, sales. Pro reads the whole store except the permanent blocks, without customer data.
Limit
It doesn't save anything.

In Service mode the data filter works on patterns, which is why you can turn Service on for 3 hours at most.

2. Customer data: a separate setting

Names, emails and addresses are hidden by default

Access to customer data is a separate setting on the “Customer data” tab in the module panel. It doesn't depend on the levels in section 1: turning on Sales, Theme or Modules doesn't reveal any personal data.

Below, the same order at the three levels of this setting.

  • Recognises personal data in other companies' module tables too
  • History entries with customer data are encrypted and by default disappear after 180 days
  • Passwords, API keys and database backups are blocked at every level
Level 1 of 3: no access
Order #1042 from the demo store, €70, as the chat sees it
Data accessblocked, default setting
Customerhidden
Emailhidden
Addresshidden
ProductsSora lantern × 2

This is how it is after installation. Products and amounts are enough to analyse sales, so the chat doesn't know who bought.

3. Backups and undo

There's always a way back

You can undo most changes with one sentence, even 40 products at once. Every day, before the first change, a backup of the whole database is made.

A sample day in the demo store
  1. 7:58
    Whole database backup
    before the first change of the day
  2. 8:15
    12 titles saved
    after “yes”, into the history
  3. 8:16
    Undo
    with one sentence

A sample day in the demo store

  • The last two database backups are kept; copies of theme and module files for 90 days, at least the last 5
  • Before saving a PHP file, the module checks its syntax so it doesn't take your store down
  • An emergency key and a restore script work even when the admin panel won't load
  • Uninstalling a module can't be undone from the history; the chat says so in the preview

Every card ends in one of three ways

Saved after “yes”, undone with one sentence, or nothing when the approval expires. There is no fourth ending.

Approved

Card status: saved, old version in the history
Sora, Google title8:15
old version: Lampiarnia - lanterns and garden lighting
new version: Sora rattan lantern, hand-woven, for the patio
APPROVED8:15, ANNA

Undone

Card status: undone, store as it was yesterday
Sora, Google title8:16
undone version: Sora rattan lantern, hand-woven, for the patio
Lampiarnia - lanterns and garden lighting
one sentence brought it back

Expired

Card status: approval expired, nothing was saved
Sora, Google titlevalid until 8:45
Lampiarnia - lanterns and garden lighting
Sora rattan lantern, hand-woven, for the patio
EXPIREDNO CHANGE MADE

Example from the Lampiarnia demo store.

4. What it never does

It won't do this, even if you ask

These aren't settings, they are limits written into the module's code. Neither a switch nor a request in the chat can change them.

  • Never: Send an email, message or invoice to a customer
  • Never: Change payments or taxes
  • Never: Change an order status
  • Never: Read a password or API key
  • Never: Create an account or change a user role

When someone hides an instruction in your store's content

A product description, comment or customer message can hide an instruction meant for AI. TellMyShop tells Claude to treat such content as text, not commands, and even if that fails, passwords, payments and taxes are blocked for good, risky areas are off by default, every change shows up as a preview first, and you can undo most of them.

5. Log and control

You know who connected and what they did

  • Connections only over HTTPS and, by default, only from the chat services' addresses
  • You see the private connection address once; a new one cancels the old one
  • Default limits: 300 calls, 150 saves and 20 file saves per hour
  • “Read only” mode in one click; an integrity check every 6 hours
Audit log, todayCSV export
  1. 09:02Connection from the chat, read modechat
  2. 09:14Preview: 12 titles, low riskchat
  3. 09:15Approval and save of 12 titlesAnna
  4. 09:40Theme switch turned on for 24 hAnna
  5. 09:41Email to the owner: wider accessmodule
example from the demo store

6. Module code

Built to PrestaShop's technical standards for modules

The same rules PrestaShop describes for modules, from database queries to uninstalling.

Safe database queries
every query built the way the platform requires
Data escaping
data shown in the admin panel and in the store is escaped
File access
module files can't be opened directly
Uninstall with a choice
keep the history or remove everything

The WordPress plugin is built to WordPress's plugin guidelines.

7. GDPR and documents

Designed to help you meet GDPR requirements

Your store, as the data controller, is responsible for compliance. Exporting and deleting a customer's data also covers the change history, and the panel has ready-made text for your privacy policy.

The seals mark data protection features in the module. They are not certificates.

TELLMYSHOP · CUSTOMER DATA PROTECTION · GDPRTELLMYSHOP · CUSTOMER DATA PROTECTION · UK GDPRTELLMYSHOP · CUSTOMER DATA PROTECTION · CCPA/CPRATELLMYSHOP · CUSTOMER DATA PROTECTION · LGPD

Questions

Can the chat change something when I'm not looking?

Every change starts with a preview, and the chat is told to wait for your “yes”. No reply, a question or a “maybe” is not approval, and approval for one preview expires after 30 minutes. Risky areas are off by default, and you can undo most changes.

What if I approve something by mistake?

You can undo most changes with one sentence or from the change history. On top of that, every day before the first change a backup of the whole database is made.

Do conversations reach TellMyShop?

No. You have conversations in your own Claude or ChatGPT account; TellMyShop doesn't see them and doesn't train models on them.

I found a vulnerability. Where do I report it?

Write to [email protected] before you publish any details.

Start with the version that only reads

We launch on 29 October. TellMyShop Free will look through your store and show a list of fixes, without saving anything.