Sellxora Resource Center
Resource Center/Policies and security/Protect provider credentials and customer data
Policies and securityPolicy and security1 min read

Protect provider credentials and customer data

Use protected settings correctly and keep secrets, payout details, and customer records out of public content and support channels.

Version 1Last reviewed 24 Sep 2026
Provider credentials belong in the protected settings area for the module that owns the integration. Collection gateways, payout providers, Marketing SMTP, social channels, advertising accounts, and AI provider configuration should not be mixed together.

Sensitive payout destinations are encrypted and should be represented in screens and logs by status or safe fingerprints. Customer names, emails, phone numbers, custom form answers, and order details should be visible only to authorized workspace users and administrators.

Common questions



Can support ask for my secret key? No. Support should request a safe error message, provider reference, timestamp, and affected route. What if a secret is exposed? Rotate it at the provider, revoke the old credential, update Sellxora, and record the incident safely.

Steps

  1. Open the module’s protected Settings page.
  2. Store credentials only in the designated encrypted field.
  3. Use masked or redacted values in screenshots and support messages.
  4. Rotate credentials immediately after suspected exposure.
Was this guide helpful?
Ask for help

Related guides