FREE shipping on all orders above ₹999
Get a free bedsheet worth ₹2699 on order above ₹5000.
Get 5% off on all orders – Use code MYTRI5.
Get 10% off on order above ₹2500 – Use code MYTRI10.
Get 15% off on order above ₹4000 – Use code MYTRI15.
Last Update: [Date]

 

1. Purpose

This Policy explains how MyTrident India ("MyTrident", "we", "us") controls access to personal data and Store systems, including who is granted access and the level of access provided. Restricting access to personal data on a need-to-know basis is a fundamental security measure and supports our obligations as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) to implement reasonable security safeguards and prevent unauthorized access.

 

2. Scope

This Policy applies to all employees, contractors, agencies, and business partners who are granted access to the MyTrident Shopify Admin, connected applications, or any systems that store or process customer personal data.

 

3. Guiding Principles

a) Least Privilege
Each user is granted only the minimum level of access required to perform their assigned responsibilities.

b) One Identity Per Person
Shared or group login credentials are prohibited. Every user must have an individual account so that all actions can be accurately attributed to a specific person.

c) Separation of Third-Party Access
External agencies, consultants, and developers are provided with limited, role-specific access for the duration of their engagement. Their access is promptly revoked once their work is completed.

d) Multi-Factor Authentication (MFA)
All accounts with access to the Store must have Multi-Factor Authentication (MFA) enabled to provide an additional layer of security.

 

4. How Access Is Controlled on Shopify

Our Store operates on Shopify, which provides a role-based access control system. We use this system as follows:

a) Roles and Permissions

In Shopify, a role is a collection of permissions assigned based on a user's responsibilities. Permissions are assigned through roles rather than individually, making access management more consistent and reducing the risk of excessive permissions.

We use Shopify's predefined roles wherever appropriate (for example, roles limited to products, catalogs, and content) and create custom roles where more specific access controls are required.

b) Store Roles vs. Organization Roles

a) Store-Level Roles: Control access to Store-specific areas such as Orders, Products, Customers, Finance, Content, and Settings.

b) Organization-Level Roles: Where applicable (for businesses operating multiple Shopify stores or using Shopify Plus), these roles manage access across stores and organizational functions such as Billing and Point of Sale (POS) administration.

c) Account Types

a) Staff Accounts: Provided to MyTrident employees who require direct administrative access to the Shopify Store.

b) Collaborator Accounts: Provided to approved agencies and external partners working on specific projects. Collaborator access is restricted to the required scope of work, requires a collaborator request code, and must be secured with Multi-Factor Authentication (MFA).

d) Sensitive Data Access

Access to customer information, order data, and financial records is restricted to authorized personnel with a legitimate business need. Administrative functions, including user management and Store settings, are limited to designated administrators.

 

5. Role Definitions (template-customise for MyTrident)


Role Typical Access Should Not Have Access To
Store Owner / Administrator Full administrative access, including user management, finance, and Store settings. Access should be limited to a small number of authorized individuals. Multi-Factor Authentication (MFA) must be enabled.
Operations / Fulfillment Manage orders, fulfillment, and basic customer information required for order processing. Finance, Store settings, user management, and application installation permissions.
Merchandising / Catalog Manage products, collections, inventory, and Store content. Customer personal data, finance, and Store settings.
Marketing Access to marketing tools, discounts, analytics, and approved marketing applications. Finance, Store settings, and the ability to export complete customer lists.
Finance / Accountant Access to financial reports and accounting functions only (using Shopify's scoped accountant access where applicable). Products, content management, and Store settings.
External Agency (Collaborator) Time-limited, role-specific access to designated Store areas necessary for the engagement. Any resources outside the agreed scope of work, including finance, user management, and administrative settings.

 

6. Provisioning, Review and De-provisioning

a) Joiners
Access is requested by the appropriate role owner, approved by the designated approver, and assigned using the appropriate Shopify role. Permission changes take effect immediately once granted.

b) Movers
When an employee's responsibilities change, their access permissions are reviewed and updated to align with their new role.

c) Leavers / End of Engagement
Access is suspended or revoked immediately when an employee or collaborator leaves the organization or their engagement ends. Shopify terminates active sessions when a user is removed or suspended, and collaborator access codes are revoked.

d) Periodic Review
User accounts, roles, and permissions are reviewed on a regular basis to identify inactive accounts, excessive permissions, and external collaborators who no longer require access. Multi-Factor Authentication (MFA) is also verified during these reviews, and any identified issues are documented and promptly remediated.

 

7. Security Baseline

a) Multi-Factor Authentication (MFA) is mandatory for all accounts with access to the Shopify Store.

b) Store ownership and billing access are assigned only to authorized personnel and are reviewed regularly.

c) Access logs and user activity are periodically reviewed to detect and investigate unauthorized access or suspicious activity.

 

8. Ownership and Review

This Policy is jointly owned by the IT/Security and Operations teams and is reviewed at least annually, or whenever there are significant changes to the Shopify platform, our organizational structure, or applicable laws and regulations.

OTP graphic
OTP graphic