Enterprise foundation
Compliance & Data Practices
A transparent operational view of the controls represented by this frontend. This page is not a certification or a substitute for jurisdiction-specific legal, security or privacy review.
Privacy & consent
Privacy, Terms and Cookies are exposed from the footer, with a persistent mechanism for resetting non-essential analytics consent.
Security boundaries
Authentication, payment-provider boundaries and server-side access controls remain separate from customer-facing navigation and presentation.
Payment handling
Checkout is handed to the configured payment provider rather than collecting payment credentials directly in the ResoFit frontend.
Member onboarding
Assessment, member authentication and future ecosystem services are routed through explicit entry points so onboarding can evolve without replacing the commerce storefront.
Measurement governance
Analytics and advertising pixels are loaded only after analytics consent in this frontend. Essential operational storage remains available where needed to provide requested functionality.
Commerce architecture
resofit.fit/shop is the primary ResoFit shopping experience for first-party ResoFlex products, ResoFit services, personalized recommendations and native checkout. shop.resofit.fit is the specialized marketplace surface for broader supplier, partner and external offers, including Jumia where applicable.
Governance boundary
Production compliance requires validation of the live Vercel environment, Supabase policies, payment webhooks, DNS, vendor agreements, access controls, data retention, incident response, backups and jurisdiction-specific obligations. The frontend should not be represented as fully enterprise-compliant until those controls have been independently verified.