Two integration models

Stateless API

Send order details, get a decision back. We process in memory and retain nothing — no Shopify sync, no stored order data. Ideal for teams with strict data policies.

Shopify connection

Prefer hands-off automation? Connect Shopify with read-only, least-privilege access. We read order data to make decisions — never write to your store.

How we protect your data

Zero retention option

With the stateless API, order data is processed in memory and discarded once the response is returned.

Encrypted end to end

TLS 1.2+ enforced on every endpoint. Stored data, where applicable, is encrypted at rest.

US-hosted

Infrastructure is hosted in the United States, aligned with US data-handling expectations.

Least privilege

We request the narrowest scopes that make the product work — read-only, nothing more.

Scoped credentials

Provider and platform credentials are stored securely and used only for the decisions you authorize.

No data sales

We never sell merchant or order data, and never share it to win an insurer's business.

How the stateless API handles data

Send

You post order details over encrypted HTTPS.

Decide

We evaluate carrier coverage and routing rules in memory.

Return

You get the decision back in the response.

Discard

Order data is dropped. Only request metadata is logged for billing and monitoring.

Security review? We'll work through your process directly. Email sam@insurrl.com.

See also our privacy practices.