Security
Last updated: 29 July 2026
Security is central to how GoBaoPay is built, in part because of what we deliberately don't do: we never touch, hold, or store your funds or your buyers' payment credentials.
How your data is protected
- Encryption in transit: every connection to GoBaoPay is served over HTTPS/TLS.
- No stored payment credentials: buyers pay through their own chosen provider (PayPal, Alipay, WeChat Pay, bank, Wise, Remitly). GoBaoPay never sees or stores card numbers, bank credentials, or provider passwords.
- Signed sessions: login sessions are cryptographically signed and verified on every request, and passwords are never stored in plain text.
- Role separation: seller accounts and the admin/owner role are strictly separated, so a seller account can never access another seller's data or platform administration.
- Infrastructure: GoBaoPay runs on Cloudflare's global network, which provides DDoS protection and edge-level security by default.
Your part in staying secure
- Keep your password confidential and unique to GoBaoPay.
- Only share a payment request link with the intended buyer.
- Contact us immediately if you suspect unauthorized access to your account.
Reporting a vulnerability
If you believe you've found a security vulnerability in GoBaoPay, please report it responsibly to support@gobaopay.com before disclosing it publicly. We take all reports seriously and will respond promptly.
