Security

Your customer list is your business. We protect it like it's ours.

A plain-English overview of how ReConnect keeps data safe. For how we use personal data, see our Privacy Policy.

1.Every business is kept separate

Each business's customers, messages, follow-ups and sales are stored with that business's identifier, and every request is checked on the server against the signed-in user's business before any data is read or changed. Identifiers sent from a browser are never trusted on their own.

Row-level security is switched on for every table in the database as a second line of defence, so data can't be read through the database's public interface even if a key were exposed.

2.The right people see the right data

ReConnect has four roles. Owners control billing and the team. Admins help run the business: settings, the WhatsApp connection and privacy tools. Managers work with all customers. Staff see the customers and follow-ups assigned to them, and can take conversations that nobody is looking after in the shared inbox. Staff can't export customers, and only owners and admins can download or delete a customer's details or handle privacy requests.

Permissions are enforced on the server for every page and every action — hiding a button is never the only protection. Removing a team member takes away their access immediately.

Riders only see their own deliveries, through a private link the business can reset at any time. Receipt and invoice links show one sale or order to whoever has the link, and are hidden from search engines.

The ReConnect team can't open your customers or conversations unless an owner turns on support access for a set time. It is read-only, every view is recorded and shown to the owner, and it can be turned off at any time.

3.Signing in

Anyone can turn on two-step login in Settings → Your account: after your password, you enter a code from an authenticator app on your phone, so a stolen password isn't enough to get in. It's required for the ReConnect team.

Sign-in is rate limited to slow down guessing, and you can sign out of every device at once. Repeated failed sign-ins raise an alert for our team to check.

4.Encryption

  • All traffic uses HTTPS, and browsers are told to always use a secure connection.
  • WhatsApp and Google access tokens, and two-step login secrets, are encrypted with AES-256-GCM before they are stored.
  • Passwords are never stored in readable form; they are hashed by our authentication provider.
  • Session, password-reset and invitation links are stored only as one-way hashes, and expire.

5.Protecting the application

  • Every form and request is validated on the server, and database queries are parameterised.
  • Requests that change data must come from ReConnect itself, which blocks cross-site request forgery.
  • Sign-in, sign-up, password reset and the contact form are rate limited to slow down guessing and abuse.
  • Strict security headers, including a Content Security Policy, and cookies that can't be read by scripts.
  • CSV exports are protected against spreadsheet formula injection.

6.WhatsApp and payments

ReConnect connects to WhatsApp only through Meta's official WhatsApp Business Platform. We never ask for your WhatsApp password and cannot access personal WhatsApp accounts. If you connect your WhatsApp Business app, its contacts and recent chats are imported through Meta only if you choose to share them. Messages sent to us by Meta are checked against Meta's signature before they are accepted.

Payments are handled by Paystack. Your card details go directly to Paystack and never reach ReConnect's servers. Payment notifications from Paystack are signature-checked and processed exactly once.

7.Monitoring and audit trail

Important actions — sign-ins, imports, exports, changes to what customers want to hear, deletions, privacy requests, team changes and support access — are recorded in an activity log with who did them and when. Owners can see their business's log in Settings → Privacy & data.

Unusual activity, such as many failed sign-ins, a very large export, many deletions at once or webhooks with bad signatures, raises an alert for our team. Errors and failed background jobs are logged so problems are noticed and fixed.

8.You stay in control of your data

You can export your customers to CSV at any time. When a customer asks, you can download everything you hold about them, or delete their details: their sales stay in your reports without their name. Customers who opt out of WhatsApp, or reply STOP, are blocked from being messaged.

You choose how long ReConnect keeps old chats, archived customers, delivery addresses and the activity log, in Settings → Privacy & data.

Owners can close the business in Settings → Close account. Everything is deleted 30 days later, unless the owner reopens it or downloads it first; we keep only records the law requires, such as billing records.

9.Reporting a security issue

If you think you've found a security problem, please tell us at our contact form and include enough detail for us to reproduce it. Please don't access other people's data or disrupt the service while investigating. We'll acknowledge your report and keep you updated.