Account authentication
MintLoop uses Clerk for creator sign in and session management. Private product routes require an authenticated account.
Security and data handling
Security is a process, not a badge. This page explains the safeguards in MintLoop and the responsibilities that remain with each creator.
MintLoop uses Clerk for creator sign in and session management. Private product routes require an authenticated account.
MintLoop verifies Razorpay signatures and checks the provider payment, order, amount, currency, captured status, and group before activating membership.
Razorpay webhook events are checked with the configured webhook secret before they can update payment and refund records.
MintLoop stores the records needed to reconcile checkout visits, payment references, memberships, refunds, renewal dates, and access events.
MintLoop currently uses a Baileys linked device session. It does not need your WhatsApp password and does not read private message content for the product workflow.
Linked device actions depend on WhatsApp, session health, network availability, and administrator permission. Creators should maintain a manual access review process.
Use a dedicated WhatsApp Business number where possible, protect administrator accounts, enable strong authentication, review connected devices, keep Razorpay KYC current, publish clear member terms, and remove access when a membership ends.
Send a clear description and relevant timestamps to mintloop.help@gmail.com. Do not email passwords, API secrets, full card data, or WhatsApp authentication files.