Skip to main content

Trust Center

Security, privacy, payments, downloads, and creator earnings safeguards.

This page describes implemented platform controls without claiming certifications, audits, or compliance programs that are not evidenced in the product.

Account protection

Passwords are hashed, sign-in endpoints are throttled, inactive accounts are blocked, and session tokens can be revoked on logout.

Payment safety

Checkout uses local/mock or configured provider lifecycles. Webhooks support signature verification when provider secrets are configured privately.

Secure downloads

Digital products are delivered only after paid-order entitlement checks through short-lived signed links and private storage metadata.

Creator and affiliate payouts

Payout queues show lifecycle, risk level, and redacted account labels. Account numbers, tax IDs, and provider credentials are not exposed by APIs.

Public-safe data

Marketplace, storefront, status, and mobile public responses avoid private emails, mobile numbers, admin notes, secret values, webhook payloads, and private file paths.

Admin accountability

Admin changes to users, products, settings, providers, payouts, search rules, support, SEO, notifications, and content are audit logged with sensitive metadata redacted.

Public-safe status

Operational transparency without private data.

Public status is limited while admin monitoring remains internal.

Private incidents, stack traces, provider payloads, customer PII, private revenue, and secrets are not shown on public status pages.

What not to share in support

  • Do not send passwords, API keys, webhook secrets, private keys, card numbers, CVV, tax IDs, or full bank account numbers.
  • Use order IDs, product titles, payout IDs, and screenshots with sensitive details hidden.
  • Trust & Safety tickets are routed to admin review without exposing internal fraud rules publicly.