PCXProgram controls / security

Minimize sensitive movement across the program

A Shopify prepaid card workflow can involve commerce data, customer contact data, eligibility evidence, communications, provider references, and operational reports. Each data class needs a purpose and owner.

01

Create a data inventory

List the fields used at intake, evaluation, communication, provider handoff, support, and reporting. Record source, purpose, sensitivity, legal basis where required, recipient, retention, and deletion or anonymization path.

02

Keep card data out of merchant workflows

Design the merchant and support experience so full card numbers, security values, credentials, and other sensitive provider data are not copied into Shopify notes, campaign tools, ordinary email, analytics, or internal tickets.

03

Plan incidents across organizations

Define detection, triage, containment, notification, evidence preservation, customer communication, and post-incident review responsibilities across merchant and provider teams. Contractual timelines should match operational capability.