Security & data handling

Customer-authorised access. Controlled data handling.

Commerlytics is being designed around explicit account authorisation, tenant-scoped data handling and controlled access to provider data.

Authorisation

Where supported, customer accounts are intended to be connected using the provider's approved authorisation process. Customers remain in control of the external accounts they authorise and can revoke access through the relevant provider.

Customer separation

The platform is designed so customer, seller and advertising-profile context is resolved explicitly and data is processed within the correct ownership scope.

Credentials and secrets

Provider credentials and secret material are not intended to be stored in public source code or ordinary project documentation.

Data minimisation

Commerlytics aims to request and retain only the data needed to provide the relevant service and to remove or de-authorise customer access when an integration is disconnected or a customer relationship ends, subject to legal and operational retention requirements.

Security contact

Security-related enquiries can currently be sent to [email protected].

This page describes current design principles of a product in development and does not claim third-party security certification.