SKQ-030

Privacy Boundary QA

Seller sees only safe data

Aasaan alfaaz

Seller ko sirf kaam ki cheez dikhni chahiye. Family private baat, wallet, admin notes, exact contact, unrelated orders aur internal finance hidden rehte hain.

Score

100%

Signals

0

Leaks

0

QA

0

QA state

Privacy QA ready. Seller-visible surfaces must pass before next public/runtime confidence.

Visibility scope

Current test scope: Owner. UI hiding is convenience only; backend customer-scope and role permission enforcement remain final.

Seller-safe fields

Allowed to show

Request title

Customer-safe need summary only

Area label

Mohallah/service area, not exact house

Item lines

Product/quantity required for seller action

Time need

Reply, pickup, delivery, or slot timing

Budget/amount label

Customer-safe amount due or budget cap when role allows

Proof need

Freshness, expiry, weight, packing, OTP/photo/QR requirement

Issue reason

Customer-safe reason, no private family story

Handover actor label

Masked rider/helper/customer pickup label

Hidden groups

Must never show to seller

Redaction tests

Family-private data

Show only family-safe request label.

Hidden
Family member names: [hidden]children/school info: [hidden]household schedule: [hidden]private family notes: [hidden]

Customer wallet/payment secrets

Show only partner evidence status label.

Hidden
wallet balance: [hidden]card/bank/provider secret: [hidden]OTP/payment token: [hidden]saved payment method: [hidden]

Admin/internal notes

Show only seller-safe action instruction.

Hidden
fraud score: [hidden]support private note: [hidden]risk label: [hidden]manual investigation comment: [hidden]

Unrelated customer orders

Show only this request packet.

Hidden
other customer basket: [hidden]other shop order: [hidden]previous private complaint: [hidden]neighbor family data: [hidden]

Exact contact/location

Show masked contact and area until dispatch gate.

Hidden
exact address: [hidden]phone number: [hidden]door note: [hidden]full map pin: [hidden]

Health/private medicine data

Show availability/expiry proof only.

Hidden
full prescription image: [hidden]diagnosis: [hidden]family illness note: [hidden]private health instruction: [hidden]

Internal finance/ledger

Show pending/held/approved/paid-evidence label only.

Hidden
platform margin: [hidden]shop settlement rule: [hidden]ledger journal: [hidden]payout approval note: [hidden]

Supplier cost/source secrets

Show public product/source confidence only when approved.

Hidden
supplier cost: [hidden]private source name: [hidden]contract terms: [hidden]margin calculation: [hidden]

Local signal scan

No obvious local leak text

This scan checks demo/local seller packets for obvious leak labels. It is not a replacement for backend permission tests.

Seller surface checks

Run QA packet

Save review evidence

Saves local QA evidence only. No production data, user permission, or customer state changes.

Last QA packets saved: 0. Result is local/demo evidence until backend tests exist.

Boundary locks

Privacy cannot be optional

Privacy Boundary QA stores audit evidence only; it does not create permissions, sessions, staff accounts, customer messages, orders, payments, ledger, inventory, dispatch, settlement, or trust changes.
Seller screens must show customer-safe request data only: item, area label, time need, budget/amount label where allowed, and proof requirements.
Seller screens must not expose family-private notes, customer wallet/payment secrets, exact address/phone, admin/fraud/internal support notes, unrelated orders, health private details, supplier cost, margin, or ledger internals.
Staff mode must reduce visibility further by role: cashier, packer, and handover person each get minimum useful fields.
Any suspected leak creates a local QA packet for FAEDA Team review; it does not auto-punish seller/customer or mutate production data.
Backend permission and customer-scope enforcement remains final authority; UI hiding is not security by itself.