Skip to content

Last updated 2026-09-27

Trust centre

How Eira keeps Myanmar shoppers and vendors clear on payments, delivery, disputes and data.

Platform registration

Address
Yangon, Myanmar

Payments are verified by the shop

Eira never collects card numbers or wallet passwords. KBZPay and Wave Pay happen inside the wallet app. The customer uploads a payment screenshot, then the shop owner reviews that screenshot in admin or Telegram before dispatching a paid order.

Orders are tracked from checkout to delivery

Each order receives a shop-prefixed code. Customers can track the order page or Telegram updates when they link Telegram; admins and Telegram callbacks use the same order state machine.

The shop and its delivery team fulfil orders

Eira provides the storefront, admin tools and Telegram delivery cards. The shop approves the order, then its paired delivery group can accept, pick up, deliver or mark a failed attempt.

Cancellations and failed deliveries follow the order state

QR orders wait for payment, move to shop approval after proof upload, then progress through confirmed, dispatching, assigned and out for delivery. Owners can reject unclear proof, cancel orders with a reason, retry failed deliveries, or complete delivered orders.

Data retention

Shops store customer name, phone, address and order history for fulfilment and reports. Payment proof image files are purged by the daily cron after the shop's proofRetentionDays setting (default 90 days); order records remain for accounting. Admin sessions expire after 30 days and expired sessions are pruned.

Security measures in the codebase

Eira sets a per-request Content-Security-Policy nonce, form-action 'self', production HTTPS upgrades, production HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy headers. Sessions use hashed random tokens in HttpOnly cookies, passwords are hashed with scrypt, and login, checkout, order lookup, Telegram verification and upload endpoints are rate limited.