Security & Privacy Standards
Metrivo is built to be privacy-friendly. We do not track visitors across websites, we secure API keys cryptographically, and we hash customer emails to protect identities.
Privacy-Friendly Web Tracking
Our client-side tracking script respect user choices and offers simple opt-out flags for your team and staging domains.
Cryptographic Data Protections
We apply industry-standard security steps to sensitive customer identities and credential records.
Webhook Integrity
To prevent spoofing or replay attacks, Metrivo requires webhook payloads to be signed by the originating payment gateway (Stripe, Razorpay, or Dodo).
Signature Verification
When configuring webhook secrets, Metrivo validates the headers against each provider's cryptographic signing specifications. Any webhook containing an invalid or missing signature is immediately rejected with a `400 Bad Request` or `401 Unauthorized` status.