Oshop (Oshop) Oshop (Oshop)
Product Pricing Customers Blog Docs
πŸ‡³πŸ‡¬ Nigeria
Sign in Start free trial
Product Pricing Customers Blog Docs Sign in

Appearance

Start Free Trial
Our commitment Platform architecture Encryption Access control Payment security Data protection Incidents Your role Responsible disclosure Compliance Contact

Security Policy

Last updated: June 21, 2026

Our commitment

Security is foundational to Oshop247. Merchants trust us with business data, customer orders, and payment workflows. We design our platform to isolate tenant data, encrypt sensitive traffic, and limit access on a need-to-know basis.

This policy summarises our security practices. For how we handle personal data, see our Privacy Policy.

Multi-tenant architecture

  • Tenant isolation β€” each merchant’s operational data is stored in a separate tenant database context
  • Central services β€” billing, signup, and platform administration use a separate central database
  • Custom domains β€” merchant storefronts can use their own domain with automatic SSL provisioning
  • Subdomain routing β€” tenant stores are served on dedicated subdomains or mapped custom domains

Encryption

  • In transit β€” all traffic to oshop247.com, admin panels, and storefronts is encrypted with TLS (HTTPS)
  • At rest β€” database and file storage use encryption provided by our cloud infrastructure
  • Secrets β€” API keys, payment credentials, and sensitive settings are stored encrypted and are not exposed in client-side code
  • Passwords β€” stored using industry-standard one-way hashing (bcrypt)

Access control & authentication

  • Role-based permissions β€” merchants can assign staff roles with granular admin permissions
  • Super admin access β€” platform operators use separate authentication with role-based permissions and activity logging
  • Session security β€” authenticated sessions expire after inactivity; CSRF protection on state-changing requests
  • Two-factor authentication β€” available for super admin accounts; merchant 2FA where enabled by plan
  • Principle of least privilege β€” internal access to production systems is limited to authorised personnel

Payment card security

Oshop247 does not store raw card numbers on our servers. Card payments are processed by PCI DSS compliant partners:

  • Paystack β€” Nigeria and supported African markets
  • Flutterwave β€” cards and local payment methods where enabled
  • Stripe β€” international subscription and checkout flows where available

Checkout flows use hosted or tokenised payment fields so card data goes directly to the processor.

Backups, monitoring & NDPR

  • Regular automated backups with encrypted storage
  • Application and infrastructure logging for security monitoring
  • Vulnerability patching as part of our deployment process
  • Compliance with Nigeria’s NDPR for lawful processing and data subject rights
  • Data processing agreements available for Enterprise customers on request

Security incidents

If we become aware of a data breach affecting personal data, we will investigate promptly, take steps to contain it, and notify affected merchants and regulators where required by law. Merchants are responsible for notifying their own customers when the breach involves customer data the merchant controls.

Your security responsibilities

As a merchant, you play an important part in keeping your store secure:

  • Use strong, unique passwords and limit admin access to trusted staff
  • Remove access for staff who leave your business
  • Keep devices and browsers updated
  • Do not share API keys or login credentials
  • Report suspicious activity to us immediately

Responsible disclosure

We welcome reports from security researchers and the community. If you believe you have found a vulnerability in Oshop247:

  • Email [email protected] with a clear description and steps to reproduce
  • Allow reasonable time for us to investigate and fix before public disclosure
  • Do not access, modify, or delete data that is not yours
  • Do not perform denial-of-service attacks or social engineering against our staff or merchants

We aim to acknowledge reports within 48 hours and will keep you informed of progress where appropriate.

Compliance & certifications

Oshop247 maintains practices aligned with:

  • NDPR β€” Nigeria Data Protection Regulation
  • PCI DSS β€” via certified payment processors (Paystack, Flutterwave, Stripe)
  • GDPR-aligned practices β€” for UK/EEA merchants where applicable (see UK data rights)
  • CCPA β€” notice for California residents (see CCPA notice)

Enterprise customers may request additional security documentation or a DPA as part of their contract.

Contact security team

Report a vulnerability or security concern

Email [email protected]

For account access issues, use support contact instead.

Oshop (Oshop)

Commerce for every African business

Get product updates and growth tips

Product

Storefront Point of Sale (POS) Inventory Management Analytics & Reports Multi-Currency Staff Management Barcode & Labels

Solutions

Fashion & Clothing Food & Restaurants Electronics & Tech Beauty & Wellness Pharmacy Wholesale & Distribution Supermarkets Professional Services

Resources

Documentation Blog Help Center Community Forum Changelog Status Page System Status

Company

About Us Careers Partners Affiliate Program Privacy Policy Terms of Service Billing Policy Cookie Policy

Support

Contact Us Live Chat WhatsApp Support Submit a Ticket Feature Requests Report a Bug Security Policy Compliance

© 2026 Oshop Ltd. Β· RC: XXXXXXX Β· Made in Nigeria πŸ‡³πŸ‡¬

Paystack Flutterwave Visa Mastercard Verve