Security
How JottoSop protects your data and transactions.
Your trust is our foundation.
JottoSop is built with security-first architecture. Every layer — from login to payout — is designed to protect both customers and sellers.
Customer Security
How we protect every shopper on JottoSop
Secure Payments via Razorpay
PCI DSSAll payments are processed by Razorpay — a PCI DSS Level 1 certified gateway. We never store your card details on our servers.
End-to-End HTTPS Encryption
TLS 1.2+Every request between your browser and our servers is encrypted using TLS 1.2+. Your personal and payment data is always in transit securely.
We Never Sell Your Data
Your name, address, phone number, and order history are used solely to process your orders. We do not sell or share your data with third-party advertisers.
Password Protection
bcryptPasswords are hashed using bcrypt with salt rounds before storage. Even our team cannot see your password in plain text.
Order & Account Alerts
You receive real-time notifications for every order placed, shipped, or cancelled. If you notice unexpected activity, contact us immediately.
COD & Refund Protection
Cash-on-Delivery orders are protected with order verification. Refund requests are reviewed within 48 hours and processed within 5–7 business days.
Seller Security
How we keep your business and earnings safe
KYC Verification
MandatoryEvery seller undergoes a mandatory KYC process before listing products. We verify PAN, GST, and business address to ensure platform authenticity.
GST-Compliant Invoicing
All transactions generate GST-compliant invoices automatically. Sellers' financial data is isolated per business account and never shared across sellers.
Role-Based Access Control
RBACSeller dashboards support staff accounts with granular permissions. You control who on your team can view orders, manage inventory, or access financials.
Secure Payouts
Seller settlements are processed only to verified bank accounts linked during KYC. Payout requests require authentication before processing.
Fraud Detection
Suspicious order patterns, unusually high COD rates, and fake review activity are flagged automatically and reviewed by our trust & safety team.
API Key Isolation
API-levelEach seller's data is scoped strictly to their business ID. Cross-seller data access is blocked at the API level — not just the UI level.
Platform Infrastructure
What runs under the hood
Hosting
Cloud-hosted with 99.9% uptime SLA
Database
Encrypted PostgreSQL with daily backups
File Storage
S3-compatible object storage with signed URLs
API Security
JWT auth + rate limiting on all endpoints
Images
User uploads scanned before storage
Monitoring
24/7 error tracking and alerting
Security FAQs
Common questions about your safety
Found a security issue?
We take vulnerability reports seriously. If you discover a security concern, please report it directly to [email protected] and we will investigate within 24 hours.
JottoSop — Digitalizing Small Businesses with ❤️ in Bengal
Last updated: March 2026 · For privacy concerns see our Privacy Policy