Firstly, please be informed that this is not any kind of advertisement nor it will be shown anywhere throughout the post.
I have created my own website, on the open-web. My website is built only for LSD due it's easy way of transportation.
The principle is simple, it uses open-web oriented towards privacy, that uses no Local-storage, or any back-end logic.
The website is only, and fully functional front-end with logic that is not stored, such as if you put LSD in Cart, and refresh, the cart is refreshed, and it does not require cookies.
The website was published third-party server, using a burner laptop and phone.
Since the code was manually built, and then I went through my own AI to check for potential zero-day vulnerabilities, however it uses JavaScript for loading...
You can surf on it without any registration, and there's not a single point of anyone's private data aside of my XMR wallets.
Important: However the logic behind it, is that once you come to checkout, it would provide you the amount of XMR required and one of 30 XMR addresses that I have, then you do can process the payment.
I would love to know few things, this is actually reason why am I typing all of this ::
Since the customer is able to checkout, and totally aside of the web-shop, from the wallet directly from sourcing XMR sent the required amount to one of the addresses provided, I am struggling with one particular thing.
It is, as I said open-web, and I would need to find a way to communicate with customers anonymously, so that my customers are actually safe from any data leaked.
The current thing is hosted on Vercel, on some free plan, adjusted to delete all tracks, as I said I did really approach this carefully, and I'm doing/building it for the past 8/9 months.
What communication service or method, should I use? Maybe PGP, through a text file into a email, even that leaves a trace, maybe even pastebin, and then encrypted.
My country is outside the EU, and we have very decent access to technology, so I do very carefully speak, move, do. We are not really advanced (at least no the law enforcement) in cyber security and similar.
I actually do not possess the product, I am somewhat of a fence-market. You pay, I accumulate, get a bulk discounts, re-route the shipments. Customers returning, and good profit margin.
I contently believe that only through social engineering, tricks, manipulation, psychology are people able to "fall" if everything is taken care of. Every each step, and you did not leave anything connected to yourself, then you're tied off.
I honestly need a good advice, I have some thing going on the IG, and people are actually sending me money upfront, because they know that they'll get their product.
You can be whatever you want, but people will remember, when you do something bad to harm your status, do not expect people to trust you.
Clear example, when all of this started I promised to the customers that shipment will arrive, no matter what. However, two days later one of the old markets, pulled the Exit-Scam, and my money was in the f.. wallet of the market.
To be fair, if you were for a long time around, then you actually felt that many, many times if you've been active, active.
Because the image of the brand was in question, I gathered money from loans to repay the customers, made quick one new pre-order to get out of the loans. Everyone was f.. happy not knowing what I pulled off in the background.
I need to know, what else to do?
I kinda like this thing, and I gave so much time into having a open-web fence-market, because I actually in that situation do not own anything, I just take orders, make them. Ship them (through Vendors).
What should I change in all this? The concept itself from my POV seems to be working.
The thing also that I need to know, what service offers me to host it, however it is built with Vite-React, so it needs the node package manager, or any terminal that can let me add packages (the react components)
I'm trying to explain in great detail, and sorry if anything of this confused you, I'm just head over-loaded because there's much that I would ask.
TL:DR of the QUESTIONS:
What communication service or method, should I use?
How to make new customers engage on the site, because it is on the open-web and sounds scatchy (However I gave maximum of my brain capacity to write this code, and front-end logic without any cookies.)
What to advance, what to change?
Is there something that I am missing in the context or not seeing something?
What hosting service, or server providing thing can I use that will not track any IP logs at all?
Is my idea stupid, or has some logic, because I'm too long, too invested to be real about it?
Also, please know that nothing of your idea, comment, burp or whatever can make me mad, angry or taunting, no ego in this. Clear anonymous, asking an anonymous.
Additionally, everything used to build it, manage it, deploy is used through a burner device from off-locations, through the VPN's and ect. ect. I did think through every single step.
Please give me some advice, realizations, ideas, arguments. Everything is acceptable <3
P.S: Few hours later, what do you guys think of PissMail + PGP?