Security and GDPR

How LiveShopia protects your data and your customers’ data: per-seller isolation, EU hosting, official WhatsApp, no blacklist between sellers, deletion on request.

Updated 11 September 2026

Your customers’ data is yours. LiveShopia processes it on your behalf, as a processor, and keeps it separate from every other seller’s.

Per-seller isolation

Each seller’s data is isolated at the database level through row-level security policies, verified automatically on every release. A query without the seller’s context returns nothing. There is no blacklist between sellers: a customer’s history stays with the seller she bought from.

Data in the European Union

The app and the database run on servers in the European Union. Backups run daily and before every update.

Official WhatsApp

The cart goes out through the WhatsApp Business Platform, Meta’s official version, from your number. We do not use WhatsApp linked through QR or other unofficial routes. Access tokens are stored encrypted.

Perimeter

HTTPS only, passwords stored with argon2, rate limiting on sign-in and public pages, webhooks accepted only with a valid signature. Team roles limit what each person sees and can do.

GDPR roles

You are the controller of your customers’ data; LiveShopia is the processor, under a data processing agreement. Marketing consents are recorded with source and date. A customer can ask for deletion; you do it from her file and we delete everything not legally required to keep.

Retention

Orders and fiscal documents are kept as long as the law requires. WhatsApp conversations and the comment log are kept for a limited time for dispute resolution, then deleted.

Security questions: office@liveshopia.com.