Security & Trust
How Wandering Merchant AI handles authentication, payments, data, integrations, and account security.
This page describes the current security and data-handling practices we can verify from the application and its connected services.
Overview
Wandering Merchant AI is designed to minimize unnecessary handling of sensitive information and uses established service providers for functions such as authentication, payments, hosting, and integrations where applicable. The sections below describe what we can verify from the current implementation.
Authentication
Wandering Merchant AI uses Base44 for user authentication. Sign-in is available with email and password, and Google social login is also supported.
Passwords are handled by the authentication provider and are not stored in readable form by Wandering Merchant AI. Password reset requests are processed through the platform’s authentication system — you can start a reset from the forgot password page.
Payments
Payments are processed by Stripe. Wandering Merchant AI does not directly store full payment card details. Card information is handled by Stripe’s checkout and payment infrastructure.
You can read more in Stripe’s privacy policy.
Encryption and data transmission
Data in transit. Traffic between your browser and Wandering Merchant AI is served over HTTPS.
Service credentials. API keys and service credentials (such as marketplace and email-provider keys) are stored server-side in the platform’s secret-management system and are not intentionally exposed in public frontend code.
Encryption of stored data at rest is managed by the underlying platform providers. Specific encryption algorithms and at-rest configurations are not separately documented here.
Data storage and backups
Application data is stored using the current Base44 infrastructure, which provides the database and file storage used by the application. Uploaded product images are stored in platform-managed media storage.
Backup and recovery capabilities are provided according to the platform’s current service configuration. The exact backup frequency, retention period, and point-in-time recovery options are not separately documented on this page.
Marketplace integrations
Wandering Merchant AI connects to marketplaces using one of two methods, depending on whether the marketplace offers a public API. We aim to request only the permissions needed for supported functionality.
| Marketplace | Connection method |
|---|---|
| eBay | Official API with OAuth connection |
| Etsy | Official API with OAuth connection |
| Shopify | Official API with OAuth connection |
| Facebook Marketplace | Browser extension (no public API) |
| Mercari | Browser extension (no public API) |
| Poshmark | Browser extension (no public API) |
| Whatnot | Browser extension (no public API) |
| Vinted | Browser extension (no public API) |
For API-based marketplaces (eBay, Etsy, Shopify), connections are established through OAuth and publishing happens server-to-server. For extension-based marketplaces, a browser extension automates form-filling within your own authenticated browser session — Wandering Merchant AI does not receive your marketplace login credentials for these services.
Account and data deletion
To request deletion of your account or personal data, contact us at cory@wanderingmerchantai.com or use our contact form.
Deletion requests are handled according to the current Privacy Policy and applicable legal or operational retention requirements. Certain records — such as payment records, fraud-prevention records, tax records, or records required to meet legal obligations — may be retained in limited form even after account deletion.
Privacy
For details about what information we collect, how it is used, and the choices available to you, read our Privacy Policy. The site uses analytics and advertising-measurement cookies (Google Analytics, Google Ads, and Google Tag Manager), which load after page content to avoid slowing the page.
Service providers and subprocessors
The following service providers process customer data as part of running Wandering Merchant AI:
| Provider | Purpose |
|---|---|
| Base44 | Application platform, hosting, database, authentication, and AI processing |
| Stripe | Payment processing |
| Google (GA4, Google Ads, Google Tag Manager) | Analytics and advertising measurement |
| Resend | Transactional email delivery |
AI listing generation is performed through the Base44 platform’s integration with large language model providers. Specific model providers are managed by the platform.
Report a security issue
If you believe you have found a security issue affecting Wandering Merchant AI, please contact us at cory@wanderingmerchantai.com with enough information for us to investigate. Please do not publicly disclose sensitive account information, credentials, or customer data.
We do not currently operate a formal bug bounty program, response-time SLA, or coordinated disclosure policy.
