TRUST & GOVERNANCE
Security is an operating control, not a claim.
The service limits access, encrypts credentials and records sensitive operational actions.
Security controls
Role-based access, encrypted Page tokens and credentials, webhook signature checks, duplicate-message protection, database transactions for orders and stock, audit records, backups and restoration tests.
Report a vulnerability
Send a responsible report to alisaad_ah@yahoo.com with steps and expected impact. Do not access other people's data or disrupt the service. We will acknowledge and assess the report.
Public authority requests
No disclosure occurs without mandatory legal review of authority, scope and legal basis. Unlawful or excessive requests are rejected or challenged where permitted, and only the minimum legally required data is disclosed through a verified secure channel.
Notice and documentation
We record the request, decision, data disclosed and people involved. The affected user is notified before disclosure unless prohibited by law or a documented risk to a lawful investigation applies.
Disclosure statement
As of the effective date, the controller has not provided Meta-derived personal data to public authorities in response to national-security requests during the preceding 12 months.