Security and data handling

Clear controls for payments, memberships, and access

Security is a process, not a badge. This page explains the safeguards in MintLoop and the responsibilities that remain with each creator.

01

Account authentication

MintLoop uses Clerk for creator sign in and session management. Private product routes require an authenticated account.

02

Payment verification

MintLoop verifies Razorpay signatures and checks the provider payment, order, amount, currency, captured status, and group before activating membership.

03

Webhook validation

Razorpay webhook events are checked with the configured webhook secret before they can update payment and refund records.

04

Operational records

MintLoop stores the records needed to reconcile checkout visits, payment references, memberships, refunds, renewal dates, and access events.

05

WhatsApp connection

MintLoop currently uses a Baileys linked device session. It does not need your WhatsApp password and does not read private message content for the product workflow.

06

Limits and fallback

Linked device actions depend on WhatsApp, session health, network availability, and administrator permission. Creators should maintain a manual access review process.

Your responsibilities

Use a dedicated WhatsApp Business number where possible, protect administrator accounts, enable strong authentication, review connected devices, keep Razorpay KYC current, publish clear member terms, and remove access when a membership ends.

Report a concern

Send a clear description and relevant timestamps to mintloop.help@gmail.com. Do not email passwords, API secrets, full card data, or WhatsApp authentication files.