Your customers’ data is yours. LiveShopia processes it on your behalf, as a processor, and keeps it separate from every other seller’s.
Per-seller isolation
Each seller’s data is isolated at the database level through row-level security policies, verified automatically on every release. A query without the seller’s context returns nothing. There is no blacklist between sellers: a customer’s history stays with the seller she bought from.
Data in the European Union
The app and the database run on servers in the European Union. Backups run daily and before every update.
Official WhatsApp
The cart goes out through the WhatsApp Business Platform, Meta’s official version, from your number. We do not use WhatsApp linked through QR or other unofficial routes. Access tokens are stored encrypted.
Perimeter
HTTPS only, passwords stored with argon2, rate limiting on sign-in and public pages, webhooks accepted only with a valid signature. Team roles limit what each person sees and can do.
GDPR roles
You are the controller of your customers’ data; LiveShopia is the processor, under a data processing agreement. Marketing consents are recorded with source and date. A customer can ask for deletion; you do it from her file and we delete everything not legally required to keep.
Retention
Orders and fiscal documents are kept as long as the law requires. WhatsApp conversations and the comment log are kept for a limited time for dispute resolution, then deleted.
Security questions: office@liveshopia.com.