Privacy Policy
Our commitments to safeguarding personal information, data processing principles, and regulatory compliance disclosures.
Legal Notice
This document constitutes a binding agreement for MagnusOp merchants and platform users. If you have questions regarding these terms, please contact our compliance team at [email protected].
Information We Collect
MagnusOp processes information in two distinct roles: as a Data Controller for merchant account administrators, and as a Data Processor on behalf of merchants for their end-customer storefront orders.
Information collected directly includes: business name, administrator email address, encrypted passwords, TOTP secret tokens, and payment settlement configuration keys.
How We Use Your Information
We use collected data solely to deliver the agreed commerce platform services:
- Provisioning and maintaining multi-tenant database partitions.
- Processing storefront checkouts and dispatching transactional order webhooks.
- Powering the localized vector search and AI Assistant querying capabilities.
- Enforcing security safeguards, rate limits, and audit logging.
Row Level Security & Data Isolation
All merchant catalog data, customer lists, order items, and ledger movements are tagged with a strict cryptographic business_id and isolated using PostgreSQL Row Level Security (RLS). No client request can query another merchant's data partitions.
Third-Party Disclosures & Subprocessors
We do not sell personal data. Information is shared strictly with approved technical subprocessors required to execute core platform operations, such as cloud hosts (Neon, AWS), email delivery providers (Resend), and licensed payment gateways (Paystack, Flutterwave).
Your Data Protection Rights
Under applicable data protection frameworks (including GDPR and NDPR), merchants and customers have the right to access, rectify, port, or request erasure of their personal records. Requests can be submitted directly through our Legal Contact channel.