Security and traceability

Protect the path from Shopify event to virtual card.

Use verified access, limited data, protected event delivery and linked records throughout eligibility, calculation, issuance and reconciliation.

This page describes the security boundaries and controls relevant to Rebate Cards. It does not claim that any control or provider can prevent every error, misuse, breach, loss or dispute.

Control model

Give each system and service provider a defined responsibility.

The merchant, Shopify connection, verification flow, Rebate Cards platform and card providers handle different data and decisions. Security begins by keeping those boundaries explicit.

01Identity and access
Authenticated account access, scoped roles and staged capability enablement for the verified business
02Commerce integrity
Authorized Shopify data and protected event handling tied to stable customer and order references
03Value traceability
Linked rules, calculations, card status, refunds, reversals and reconciliation records

Security layers

Apply controls to the actual e-commerce flow.

Collect only what is needed, limit access by responsibility and retain enough history to explain a decision or correction.

01

Account access

Account controls protect merchant access while staged enablement limits sensitive capabilities to the verified and approved program state.

  • Use authenticated sessions and role-appropriate access for merchant and operational responsibilities.
  • Review access when responsible people, stores or program duties change.
02

Data minimization

Use only the Shopify, contact, verification and card-related data required for onboarding, eligibility, issuance, support and defined records.

  • Avoid copying unrelated customer or store data into the program record.
  • Limit field visibility and retention to the applicable purpose and responsibility.
03

iComply verification boundary

iComply provides the workflow used to verify the company and relevant people during onboarding and review.

  • Keep verification status and provider responsibilities distinct from merchant program rules.
  • Do not describe iComply as the virtual card issuer or payment network.
04

Shopify authorization and events

The native connection uses authorized store access and supported events as the commerce source for customer, order, fulfillment and refund decisions.

  • Validate incoming event authenticity and apply controlled retry and duplicate handling.
  • Keep store and order identifiers attached to downstream calculations and adjustments.
05

Sensitive values and providers

Protect credentials and sensitive values in the systems responsible for them, while keeping card-provider operations within the applicable provider boundary.

  • Restrict secret and credential access to the service paths that require it.
  • Do not expose full card or sensitive verification data in general program screens or support messages.
06

Audit trail and reconciliation

Preserve the relationship between the source event, rule version, calculation, approval, card status and every later adjustment.

  • Use linked entries for corrections and reversals instead of silently replacing history.
  • Assign unresolved differences and support cases to an accountable operating role.

Security sequence

Review identity, data, events and value as one chain.

The security review should follow the path the real data and approved rebate value will take.

  1. 01

    Verify the business

    Confirm the company and relevant people through the iComply workflow before sensitive program capabilities are enabled.

    OutputVerification state
  2. 02

    Authorize the data source

    Confirm the Shopify store, requested access and supported event scope required by the approved program.

    OutputCommerce data scope
  3. 03

    Protect program operations

    Assign roles for rules, funding, calculation review, card actions, refunds, support and reconciliation.

    OutputAccess and control map
  4. 04

    Review evidence and exceptions

    Confirm that event failures, duplicates, rule changes, adjustments and provider responses retain a usable history.

    OutputOperational readiness decision

Security outcomes

A controlled record without unnecessary data exposure.

The goal is a program that can authenticate access, trust its source events, explain value movements and correct exceptions proportionately.

01

Scoped access

Capabilities and data are available according to the verified business, approved program and operating responsibility.

02

Trusted event chain

Supported Shopify events remain tied to the store, customer, order and effective program rule.

03

Traceable value

Calculation, issuance, refund, reversal and reconciliation records preserve the reason and authority for each change.

Common questions

Define the program clearly.

01Does iComply issue the virtual rebate card?

No. iComply provides verification services. Card issuance and payment functionality are handled through the applicable card providers and program agreements.

02What Shopify data is relevant to a rebate program?

The approved scope can include supported store, customer, order, line-item, fulfillment and refund data needed for eligibility, calculation, adjustment and reconciliation.

03Can security controls eliminate all fraud or errors?

No. Controls can reduce exposure, detect unusual events and support investigation and correction, but they cannot guarantee that every misuse, error or loss will be prevented.

04Where can the virtual card be used?

Use depends on the payment network, issuer, program, jurisdiction, merchant category or other controls, available balance and applicable card limits.

Verified Shopify onboarding

Start the account and verification path.

Open your Shopify account, authorize the store and complete the required review before protected self-service capabilities are enabled.

Open your Shopify account