Business isolation
Merchant workspaces must remain separate.
MerchantPilot is designed around separate business contexts for products, FAQs, conversations, orders, broadcasts, settings, and lead review.
- Access should be limited to authorized users for the relevant business.
- Operational states should support traceability and review.
- Public lead forms do not create tenant workspaces or subscriptions.
Credential protection
Provider credentials must stay out of public copy and commits.
MerchantPilot should use dedicated MerchantPilot environment configuration for future provider setup. Secrets, tokens, Meta app details, webhook secrets, and payment keys must never be exposed in public pages or documentation.
Final privacy, retention, deletion, transfer, and data processing language requires legal review.