How we safeguard customer and seller data, how payments are protected, and how to report a security issue.

1) Overview

What to find here: our security approach and commitments.

Likepax uses layered technical and organizational controls to protect information from unauthorized access, loss, or misuse. We review and improve these controls on an ongoing basis.

2) Platform & Infrastructure

  • Hosted on Hostinger’s secure cloud infrastructure with 24/7 monitoring and hardened server configurations.
  • Encryption in transit via TLS 1.2+; encryption at rest (AES-256) for stored data where supported.
  • Access to production systems restricted to authorized personnel with MFA and least-privilege roles.
  • Regular patching, vulnerability scanning, and vendor risk reviews.

3) Payment Security

Payments are processed by PCI DSS–compliant gateways (e.g., WooCommerce Payments, PayPal). Likepax does not store full card numbers or CVV codes. Tokens are used for repeat charges where applicable.

4) Data Handling & Retention

We collect only what’s necessary to fulfill orders, support customers, prevent fraud, and meet legal obligations. Personal data is retained only as long as needed for those purposes, then deleted or anonymized. Data requests: privacy@likepax.com.

5) Marketplace Data Sharing

For orders fulfilled by third-party sellers, we share limited data (e.g., name, shipping address, order details) so the seller can deliver your purchase. Sellers must protect this data under our Seller Agreement and applicable laws.

6) Incident Response & Notifications

We maintain a documented incident response plan. In the unlikely event of a breach, we act to contain, assess, and remediate, and we notify affected users and regulators when required by law.

7) Responsible Disclosure

If you discover a vulnerability, please email security@likepax.com with a clear description and steps to reproduce.

  • Do not publicly disclose before we confirm and fix.
  • Do not access, modify, or exfiltrate customer data.
  • Avoid service disruption or privacy impact during testing.

We review all good-faith reports and will acknowledge valid submissions.

8) Compliance & Standards

  • PCI DSS Level 1 (via WooCommerce and payment processors).
  • GDPR and CCPA/CPRA rights supported (access, deletion, portability, opt-out).
  • Routine assessments of third-party apps and integrations.

9) Contact

Likepax LLC

[Insert Your Company Address Here]

USA

Security: security@likepax.com

Privacy: privacy@likepax.com