Authorised Page
Access is granted by the merchant and limited to the eligible Business Page it selects.
Data and security
Our security statements reflect the current architecture, not certifications or audits that ComeSeeBuy does not yet hold.
Access is granted by the merchant and limited to the eligible Business Page it selects.
Incoming Meta webhook events are checked against a signature based on the app secret.
A repeated event delivery must not create a second reservation or a second message.
We do not store payment-card numbers or raw webhook payloads when a normalised event and payload hash are sufficient.
Public traffic uses HTTPS; secrets are kept outside the source repository.
Disconnecting stops future access, while a verified request starts deletion or irreversible anonymisation of eligible data.