Safety and privacy

Claude never changes your shop behind your back. This page explains, in plain words, how you stay in control and what happens to your data. The section at the end is for your IT person or developer.

Nothing changes without your yes

Every change works in three steps:

  1. Preview. Claude shows you what it wants to change: the old text and the new text, old and new price, and any warnings.
  2. You approve. Claude waits. Only when you reply "yes" does it save.
  3. Save. The change is saved the same way as when an employee clicks Save in the back office.

A preview is valid for 30 minutes and works once. If someone changes the same product in the back office in the meantime, Claude has to show you a new preview.

Reading (audits, searches, reports) changes nothing and needs no approval.

Everything can be undone

  • Ask "What did you change yesterday?" and Claude shows the list.
  • Ask "Undo that change" and Claude restores the earlier value, again after a preview.
  • Theme files: a backup is made before every change, and any backup can be brought back.
  • Page addresses: Claude changes the address back and checks that the old one redirects.

You choose what Claude can touch

  • After installation Claude can only read.
  • Prices and promotions are off until you turn them on.
  • Changes to the look of your shop need a separate service connector that works only from approved addresses.
  • Claude works as its own employee with only the permissions you give it. The shop's log shows everything it did.
  • There is a limit on how much Claude can do per hour: 120 actions, of which at most 60 changes.

Extra safety for prices

  • A price can't be set to 0.
  • A price change of more than 30% needs your extra approval.
  • A sale above 90% off needs your extra approval; above 50% you get a warning.
  • New discount codes start switched off. You check them before customers can use them.

Your customers' data

Today: the tools don't give Claude your customers' personal data. Sales reports show products and amounts, without names. Error logs hide emails and phone numbers.

Planned for version 2.6 (described before it ships; this box goes away once it's in the module):

  • The module finds personal data on its own. It recognises every table holding emails, first and last names, phone numbers, addresses or IP addresses, including tables from other vendors' modules. You don't have to point at anything.
  • You pick one of three levels:
    • No access. Claude doesn't see those tables at all.
    • Hidden data (default). Claude sees customer and order numbers, counts and amounts. Names, emails, addresses and phone numbers are masked, e.g. j***@g***.com. Claude can say "this customer ordered 3 times" without knowing who it is.
    • Full access for a few hours. For 1 to 24 hours, then it switches itself off. You type the reason when you turn it on, e.g. "complaint about order 1234". Every switch-on is logged.
  • Files Claude won't open. Server logs, customer files (upload/, download/), database dumps, archives, .git and files with passwords are always blocked. When Claude reads the error log, emails and IP addresses are hidden.
  • Encrypted change history. If the change history or a file backup contains personal data, it's stored encrypted. The key lives in a file outside the database, so a leak of the database alone doesn't expose it.

Where your data goes

  • The module runs on your own server.
  • When Claude reads something, it goes from your shop to your Claude account at Anthropic. Anthropic's terms apply to your conversations.
  • TellMyShop doesn't receive your products, orders or customers. The licence check (from version 0.4.0) sends only your licence key, domain and version numbers.

Text in your shop is not an instruction

Product descriptions or pages can contain any text, including text that looks like a command. Claude treats it as content, not as instructions. And nothing is saved without your approval anyway.

Keep your connector address secret

The connector address contains a secret key, like a password. Don't share it. If it leaks, generate a new one in the module settings.

Technical details

Authentication. Static tokens, no OAuth in 0.3.0 (Roadmap). Token in the URL (?token=) or Authorization: Bearer. Only the SHA-256 hash and a prefix are stored; the full token is shown once. A URL token can land in web server and proxy logs: prefer the header where the client supports it and rotate the token if it leaks.

Two connectors. Daily token: core, block 1 Content & SEO, block 2 Commerce. Service token: additionally blocks 3-5, accepted only from IPs on the allowlist (mandatory; default Anthropic range 160.79.104.0/21). Test token for "Test connection": 2 minutes.

Endpoint protections (src/Endpoint.php):

ProtectionValue
Master kill switchTurns the endpoint off
TransportHTTPS only
IP lockoutAfter 20 failed attempts in 10 minutes
IP allowlistOptional for daily, mandatory for service
Originclaude.ai and claude.com only
Rate limits120 calls and 60 writes per hour per connector; ps_write_theme_file 20 per hour
Block checkRepeated on every call
PermissionsPer back-office tab and action of the connector employee (ExecutionContext::requirePermissions)

Writes. change_token = HMAC of tool, arguments and a hash of the "before" state; 30 minutes, single use; execution is blocked if the data changed after the preview. Saves go through ObjectModel (ObjectWriter): per-field validation, only changed fields, actionObject…Update* hooks, PrestaShop log entry with the connector employee ID, change history. Details: Specification §5.

Theme. Smarty whitelist and test compile, JSON check, warnings for new scripts and external domains, backup before each write, parent theme read-only.

Customer data. Customers' personal data is masked before it is passed to Claude, with a separate switch independent of the blocks; in service mode customer tables are excluded from SQL by default. Logs mask emails and phones.

Personal data in 2.6 (planned, spec: plugin/ochrona-danych.md). Table detection by column names from INFORMATION_SCHEMA (dictionary email, firstname, lastname, phone, address1, ip_address… plus patterns), including third-party module tables; one filter before any tool returns a result. Levels: none / pseudonymised (masks deterministic within a conversation, HMAC with a key rotated every 24 h) / time-limited full access, 1–24 h, with a stated purpose and a log entry. Files: var/logs, upload/, download/, *.sql, *.gz, archives, .git, .env, app/config/parameters.php blocked after realpath(); emails, IPs and tokens masked when logs are read. History and backups: personal-data fields encrypted with libsodium, key in a file outside the database (0600). Limitation: a full server compromise (files and database) also exposes the key; encryption protects against a database-only leak. Pseudonymised data is still personal data under the GDPR (recital 26), so the shop remains the controller.

Not needed: PrestaShop Account, Eventbus. that no store content leaves the store except to Claude.

Checklist for IT

  • Dedicated employee and profile, not SuperAdmin.
  • Read-only mode on until the merchant has tested reads.
  • Commerce off unless needed; service token generated only if block 3 is needed.
  • IP allowlist reviewed; daily allowlist set if your network policy requires it.
  • Connector address stored as a secret; header auth where possible.
  • Database backups scheduled, independent of TellMyShop.
  • ps_check_shop_health run before larger changes.

PrestaShop is a registered trademark of PrestaShop SA. Claude is a trademark of Anthropic. TellMyShop is not affiliated with either.

Last updated: 2026-10-04