Security, privacy and compliance for global e-commerce sellers
Connect your catalogs and data to our AI-platform with military-grade encryption, strict access controls, and full adherence to international data privacy standards.
Trust at 24.online
Trust built into every step of your e-commerce workflow
Connect your catalogs, feeds, and sales data with confidence — protected by encryption, strict access controls, clear security practices, and clear policies on how your data and AI work together.
Security and data-protection program
Security
End-to-end protection for your commerce data through advanced encryption and granular access controls.
Learn more →Compliance
Structured processes and documentation that keep your operations audit-ready at all times.
Learn more →Privacy
Complete transparency on how your data trains AI models with strict subject access rights and clear policies.
Learn more →Reliability
Mission-critical uptime guaranteed by 99.9% SLAs and robust infrastructure across multiple global regions.
Learn more →Four pillars that hold our platform together
Security, compliance, privacy, and reliability — engineered as one system, not bolted on later.
End-to-end encryption, role-based access, SSO, and continuous testing keep your catalogs, images, and sales data protected at every layer.
Clear security documentation and data-processing agreements give your legal and security teams what they need.
You stay in control of your data. Exercise full data subject rights and choose how your content is used in our AI features.
A 99.9% uptime SLA, transparent live status, and a published uptime guarantee — so AI workflows keep running when your business needs them.
Security at a glance
A layered approach that protects seller data from the moment it enters our platform to the moment it leaves.
Every connection to 24.online is encrypted in transit, and your stored data — catalogs, product images, descriptions, and sales feeds — is encrypted at rest with managed keys.
Access is governed by role-based permissions and SSO, so only the right people on your team and ours can reach the right data — and every action leaves an audit trail your admins can review or export.
We test ourselves the way attackers would and act quickly on every reported vulnerability.
Policies and documents you can verify
Clear policies, honest statuses, and the documents your legal and security teams need to move fast.
We define clear protocols for how we collect, process, and protect your marketplace data, ensuring total transparency in our operations.
Our services use cookies strictly for performance analytics and essential platform functionality, with no tracking for third-party advertising purposes.
We process your product catalogs, imagery, and listing feeds with strict isolation, ensuring your data is never used to train global public models.
Your data, your rights
- ✓ Access your personal data
- ✓ Export your account information
- ✓ Correct inaccurate listings or records
- ✓ Request permanent data deletion
- ✓ Withdraw consent for processing
Privacy and control over your data
Your catalogs, your customers, your decisions — we set clear rules and let you act on them.
Privacy Policy
What we collect, why we collect it, and how long we keep it — written in plain language, mapped to the actual data flows inside 24.online.
Cookie Policy
The cookies and similar technologies we use to run the service, measure performance, and remember your preferences — with granular controls in your account.
AI Data Usage Policy
How we treat seller catalogs, product photos, descriptions, and feeds inside our AI features — what gets used, what stays out, and how you opt in or out.
Your data, your rights
- Access your data at any time
- Export it in a portable format
- Correct inaccurate information
- Delete what you no longer need
- Withdraw consent for AI processing
See our list of subprocessors for third-party operations.
How we use your data with AI
Three direct answers to the questions sellers ask us most often.
We don't train on your content by default
Your product catalogs, images, descriptions, and sales feeds are not used to train our underlying AI models. On Enterprise plans, you can sign explicit agreements that further restrict any data use, and on free and self-service plans you can opt out in your account settings.
A short list of vetted sub-processors
AI features run on infrastructure provided by a small set of vetted vendors covering hosting, model inference, and storage. Each vendor is bound by data processing terms aligned with our own commitments to you. subprocessors page
Opt out and delete on your terms
You can disable AI improvements based on your content at any time, request deletion of your data, and confirm removal from active systems within the timelines set out in our policy. We keep an audit log of these requests so your team can demonstrate compliance.
Live system status
Monitoring all marketplace API endpoints and AI worker nodes for real-time performance optimization.
Open status page ↗RELIABILITY YOU CAN PLAN AROUND
Real numbers, a live status page, and a guarantee that holds us accountable.
SSO
Seamless login with SAML and OIDC integrations.
Access Control
Granular roles and groups for team management.
Audit Logs
Detailed activity tracking with easy export options.
Data Residency
Custom DPA and region-specific data hosting.
Live system status
Track every service in real time — AI Listings, Photos, Infographics, API, and integrations. Subscribe to incident alerts and follow scheduled maintenance windows.
Talk to security team
Discuss our security practices and custom deployment needs.
Built for enterprise security teams
The controls, contracts, and visibility your security, legal, and procurement reviewers expect — without slowing your rollout.
Single Sign-On (SAML & OIDC)
Enforce SSO across your entire team with SAML 2.0 or OIDC, integrated with your identity provider in minutes.
Granular Access Control
Define roles, groups, and permissions down to the catalog and workspace level, so people see only what they need to.
Exportable Audit Logs
Every meaningful action is logged and exportable to your SIEM, giving your security team a clean evidence trail.
Custom DPA & Data Residency
Sign a tailored Data Processing Agreement and choose where your data is stored across our supported regions.
Ingest
Connect your catalog, product feeds, and assets via secure API or direct integration.
Processing
AI generation and optimization workflows running in isolated, encrypted environments.
Storage
Secure data residency options tailored to your regional compliance requirements.
Usage
Strict access control policies, SSO integration, and full audit logs for visibility.
Deletion
Data lifecycle management ensuring complete removal per your retention policies.
Talk to security team
Send us your security questionnaire, request a deep-dive review, or get answers tailored to your industry and rollout plan.
How we protect seller data, step by step
A clear view of how your information moves through 24.online — from the moment you connect a catalog to the moment data is removed.
Ingest
Connect your catalog, feed, or images through the web app, public API, or one of our marketplace and platform integrations — all over encrypted channels.
Processing
AI features for listings, copy, photos, and infographics process your data inside isolated environments, with encryption applied throughout.
Storage
Your data is stored in the region you select, encrypted at rest, with key management aligned to industry standards.
Usage
Access is gated by roles, SSO, and permissions, and every action is captured in audit logs for full visibility.
Deletion
When you request deletion or end your subscription, your data is removed from active systems on a defined schedule, with confirmation provided to your admins.
Trusted Infrastructure
THE VENDORS THAT HELP US SERVE YOU
A short, transparent list of the partners we rely on — and how we keep you informed when it changes.
We work with a small group of vetted sub-processors to run the platform — covering cloud hosting, AI infrastructure, email delivery, analytics, and payments. Every vendor is bound by data processing terms aligned with our own commitments to you. When we add or replace a sub-processor, we publish the change in advance, and customers subscribed to updates receive a notification before the change takes effect.
Current categories
- Cloud hosting & storage
- AI model infrastructure
- Email & transactional delivery
- Product analytics
- Payments & billing
- Customer support tooling
Explore Our Trust Center
Access detailed security documents, policies, and reports. Request NDA-protected items directly through our portal.

Everything in one place — the Trust Center
Your single source of documents, policies, and reports. Public materials are downloadable on the spot; sensitive items are available under NDA on request.
Responsible AI Training
We do not train our generative models on your private seller data, inventory metrics, or campaign performance history.
Content Transparency
Every AI-generated listing description and image is metadata-tagged to ensure clear disclosure to marketplaces.
Fact-Based Optimization
Our AI agents operate within strict guardrails to prevent hallucination of product features or specifications.
TRUSTED BY SELLERS WHO CAN'T AFFORD TO COMPROMISE
From global enterprise brands to fast-growing private label sellers — teams choose 24.online because the controls match the ambition.
FREQUENTLY ASKED QUESTIONS
We employ AES-256 encryption at rest and TLS 1.3 in transit for all marketplace assets. Learn more about our technical safeguards in our encryption standards documentation.
Access is strictly limited via role-based access control (RBAC) and audited by our security team. Our access policy ensures only essential personnel can view metadata.
No. Your proprietary catalog content is strictly segregated and never used to train public or shared models. View our AI data privacy commitment.
We offer data residency options allowing you to pin your workspace to specific regions. Check our data residency guide for available locations.
We provide a permanent data wipe procedure initiated upon request or subscription termination. Details are available in our retention policy.
Our incident response protocol mandates direct, timely notification to all affected accounts. See our incident response plan.
We access only the read-only catalog and sales performance data necessary for AI optimization. Learn more about our API security scope.
Yes, we support enterprise-grade SSO and provide standard or custom DPA agreements. Contact us via our enterprise sales portal.
We maintain immutable backups for disaster recovery to ensure your business continuity. Read our recovery protocols.
Frequently asked questions
Quick answers to what sellers, security reviewers, and procurement teams ask us most.
READY FOR A DEEPER LOOK?
Open the Trust Center for documents and policies, or talk directly to our security team about your specific requirements. Our security team is ready to help and typically responds within one business day.