Security

Who can see what, and why.

The question merchants actually ask is whether a driver can see the rest of the business. This page answers that, and is clear about what we are not yet publishing.

How access works

Six things that are true of the shipped product.

01

Drivers see one filtered list

A driver’s orders are filtered on our side before anything reaches their phone. There is no request they can make that returns another driver’s round, or the rest of your orders.

02

Drivers never get a Shopify account

The portal is a separate web app with its own sign-in. No driver is issued Shopify admin access, so no driver can reach your products, customers, takings or settings.

03

Sign-in is by phone, and you control it

A driver signs in with the number on their driver record and a code sent by text. Removing that record, or unticking Active, ends their access.

04

Shopify stays the record

Wunder Delivery reads your Shopify orders and writes back specific things — a completed delivery, a printed tag. It does not build a parallel copy of your order book.

05

Your admin access is Shopify’s

The app runs inside your Shopify admin. Who can open it is decided by your Shopify staff permissions, so there is no second set of accounts to manage or forget to revoke.

06

Every write is on the order timeline

When the app changes something on an order, Shopify records it on that order’s timeline like any other app or staff member. You can always see what happened and when.

What the app asks Shopify for

To show you your own orders, print them and pass a completed delivery back, the app needs to read your order and customer information and write fulfilment updates and tags. Shopify shows you exactly which permissions are being requested when you install, and you approve them there.

It does not need — and does not ask for — access to your payment details, your Shopify billing, your theme code or your staff accounts.

What we are not claiming yet

We would rather leave a gap here than publish something we have not verified. This page carries no certification claims, no uptime guarantee, no encryption specifics, no hosting-region statement and no subprocessor list, because those need confirming and reviewing before they appear on a page merchants rely on.

If your business needs any of that in writing before you can adopt a tool, ask us. We would rather answer a specific question accurately than publish a general reassurance.

Reporting something

If you believe you have found a security problem, email hello@wunderdelivery.com with enough detail to reproduce it. Please give us a reasonable chance to fix it before publishing anything.

Have a security question?

Ask the specific one. We will answer it, or tell you plainly that we cannot yet.