Trust Center

    Security, Privacy & Compliance

    We take protection of your account, wallet, and personal data seriously. This page summarises the controls we have in place and the practices you can expect from us.

    Account & Authentication

    • Email + password and Telegram-based sign-in.
    • Passwords are hashed by our auth provider — never stored in plaintext.
    • Email verification required before purchases on linked accounts.
    • One-time login codes (OTP) expire after 30 minutes.
    • Admin role is stored in a separate, server-only table to prevent privilege escalation.

    Data Protection

    • All traffic is served over HTTPS / TLS.
    • Row-Level Security (RLS) is enabled on user-facing tables so you can only read and modify your own records.
    • Privileged server-side actions (transfers, escrow, refunds) run inside audited database functions with row-level locking.
    • Reseller cost prices and other sensitive fields are hidden from anonymous visitors.
    • Backups are managed by our cloud provider (Supabase).

    What We Collect

    • Account details: name, email, optional avatar, optional Telegram ID.
    • Wallet & order history needed to fulfil purchases and show your records.
    • Basic device / browser metadata for fraud prevention and analytics.
    • We do not sell your personal data to third parties.

    Payments

    • Card / UPI payments are processed by Razorpay; we never see or store full card numbers.
    • Crypto payments are verified via Binance Pay webhooks with idempotent server-side checks.
    • Wallet operations use row-level locking to prevent race conditions and double-spend.
    • Escrow deals are mediated by admins, with a 2% fee deducted on release.

    Reporting a Vulnerability

    If you believe you've found a security issue, please email us immediately. Do not publish details publicly until we've had a chance to investigate and ship a fix. We aim to acknowledge reports within 72 hours.

    Report a security issue

    Your Responsibilities

    • Use a strong, unique password for your account.
    • Never share your OTP, login code, or password with anyone — including support.
    • Verify the domain is cheapest-premiums.in before logging in.
    • Report suspicious messages claiming to be from us.

    This page describes our current practices and is updated as our systems evolve. It is not an independent certification.

    See also our Terms & Conditions.