Encryption and transport
All traffic uses HTTPS with HSTS. Browser security headers reduce clickjacking, sniffing, and mixed-content attacks. Data syncs to a managed cloud database with account-scoped access controls.
Trust
Last reviewed: 20 August 2026. Security mail: security@luckymart.biz.
All traffic uses HTTPS with HSTS. Browser security headers reduce clickjacking, sniffing, and mixed-content attacks. Data syncs to a managed cloud database with account-scoped access controls.
Ledger rows, products, and uploads belong to your account and selected stores. Other MR.STORE customers cannot read your data. Access control is enforced in the cloud, not only in the browser.
Owner 2FA is included on Free. Turn on authenticator 2FA for the owner login. Staff sign in with their own email after you invite them on Pro. You can revoke access without changing the owner password. Do not share the owner login.
Owner accounts can export store data from Settings. Ask us to delete an account and we remove the store records we hold. Keep a CSV backup before you retire a phone.
We do not sell your sales history. We do not use your vendor invoices to train public ad models. We do not share your ledger with other store owners.
Email security@luckymart.biz. Include steps to reproduce. Do not send live secrets in the first mail. See security.txt.