Security Policy
Last updated: June 21, 2026
Our commitment
Security is foundational to Oshop247. Merchants trust us with business data, customer orders, and payment workflows. We design our platform to isolate tenant data, encrypt sensitive traffic, and limit access on a need-to-know basis.
This policy summarises our security practices. For how we handle personal data, see our Privacy Policy.
Multi-tenant architecture
- Tenant isolation β each merchantβs operational data is stored in a separate tenant database context
- Central services β billing, signup, and platform administration use a separate central database
- Custom domains β merchant storefronts can use their own domain with automatic SSL provisioning
- Subdomain routing β tenant stores are served on dedicated subdomains or mapped custom domains
Encryption
- In transit β all traffic to oshop247.com, admin panels, and storefronts is encrypted with TLS (HTTPS)
- At rest β database and file storage use encryption provided by our cloud infrastructure
- Secrets β API keys, payment credentials, and sensitive settings are stored encrypted and are not exposed in client-side code
- Passwords β stored using industry-standard one-way hashing (bcrypt)
Access control & authentication
- Role-based permissions β merchants can assign staff roles with granular admin permissions
- Super admin access β platform operators use separate authentication with role-based permissions and activity logging
- Session security β authenticated sessions expire after inactivity; CSRF protection on state-changing requests
- Two-factor authentication β available for super admin accounts; merchant 2FA where enabled by plan
- Principle of least privilege β internal access to production systems is limited to authorised personnel
Payment card security
Oshop247 does not store raw card numbers on our servers. Card payments are processed by PCI DSS compliant partners:
- Paystack β Nigeria and supported African markets
- Flutterwave β cards and local payment methods where enabled
- Stripe β international subscription and checkout flows where available
Checkout flows use hosted or tokenised payment fields so card data goes directly to the processor.
Backups, monitoring & NDPR
- Regular automated backups with encrypted storage
- Application and infrastructure logging for security monitoring
- Vulnerability patching as part of our deployment process
- Compliance with Nigeriaβs NDPR for lawful processing and data subject rights
- Data processing agreements available for Enterprise customers on request
Security incidents
If we become aware of a data breach affecting personal data, we will investigate promptly, take steps to contain it, and notify affected merchants and regulators where required by law. Merchants are responsible for notifying their own customers when the breach involves customer data the merchant controls.
Your security responsibilities
As a merchant, you play an important part in keeping your store secure:
- Use strong, unique passwords and limit admin access to trusted staff
- Remove access for staff who leave your business
- Keep devices and browsers updated
- Do not share API keys or login credentials
- Report suspicious activity to us immediately
Responsible disclosure
We welcome reports from security researchers and the community. If you believe you have found a vulnerability in Oshop247:
- Email [email protected] with a clear description and steps to reproduce
- Allow reasonable time for us to investigate and fix before public disclosure
- Do not access, modify, or delete data that is not yours
- Do not perform denial-of-service attacks or social engineering against our staff or merchants
We aim to acknowledge reports within 48 hours and will keep you informed of progress where appropriate.
Compliance & certifications
Oshop247 maintains practices aligned with:
- NDPR β Nigeria Data Protection Regulation
- PCI DSS β via certified payment processors (Paystack, Flutterwave, Stripe)
- GDPR-aligned practices β for UK/EEA merchants where applicable (see UK data rights)
- CCPA β notice for California residents (see CCPA notice)
Enterprise customers may request additional security documentation or a DPA as part of their contract.
Contact security team
Email [email protected]
For account access issues, use support contact instead.