Trust & safety
Safety model
Agents drive; humans approve. The submitted edition keeps the commerce path between the shopper-controlled client and Shopify.
Hard boundaries
- No Tilda payment handling. Order and payment confirmation happen on Shopify-hosted checkout.
- No Tilda shopper login. The app does not issue endpoint tokens or collect shopper account credentials.
- No autonomous purchase claim. The client should ask the human before creating a purchase session or following a checkout handoff.
- Shopify is the commerce authority. Price, inventory, market availability, cart, tax, shipping, and checkout come from Shopify.
Data handling
- Direct UCP path — shopper queries, carts, checkout URLs, customer information, orders, addresses, and payment data do not pass through Tilda.
- Embedded-app data only — Tilda stores the encrypted Shopify installation/session credential and merchant-scoped app state.
- Client responsibility — a merchant or shopper separately choosing a compatible client is responsible for that client's provider and privacy terms.
See the Privacy Policy and Terms for full detail.