Security and loss prevention

Self-checkout without the shrinkage problem

The main objection to mobile self-checkout is loss prevention. Leav addresses it directly with an AI exit verification layer built into every plan. No additional hardware required.

AI
exit verification on all plans
Real-time
mismatch alerts to staff dashboard
0
extra hardware to install

How AI exit verification works

The shopper pays. The exit checks.

When a Leav session completes, the system has a complete record of every scanned item: product ID, quantity, and visual signature from the barcode scan frame. When the shopper reaches the exit, their device displays a QR code that staff or a Leav-connected tablet can scan.

The exit scan reads the session data and the AI layer compares the displayed cart against what the phone's camera captured during the shopping session. Item count mismatches and unscanned items detected at exit generate an alert in the staff dashboard within two seconds.

Staff do not need to stop every shopper. The dashboard shows a live queue of exit scans and flags the ones that need a secondary review. Clean sessions pass automatically.

1
Shopper scans items
Camera captures visual signature of each scan event
↓
2
Payment completes
Session sealed with cart contents and scan signatures
↓
3
Exit QR scanned
AI compares cart vs. exit capture in under 2 seconds
↓
PASS - Exit clear REVIEW - Flag for staff

Security layer details

Multiple layers from scan to exit

01. Scan session binding

Each shopping session is bound to a single device and location. A session QR code cannot be reused across exits or shared between devices. Sessions expire after a configurable timeout if the exit scan is not completed.

02. Scan-frame visual capture

During barcode scanning, the Leav camera layer captures the frame at the moment of each successful scan. These frames are stored with the session and used during exit comparison to detect items that may have been scanned without being placed in the cart.

03. Exit mismatch detection

The AI model compares the sealed cart record with the exit visual capture. It flags sessions where item count differs by more than one, where item categories do not match, or where unusual scan patterns are detected. Sensitivity is configurable per location.

04. Staff alert and review queue

Flagged sessions appear in the staff dashboard within two seconds of the exit scan. Staff see the session ID, the flag reason, and the session's scan history. They can approve or escalate from the dashboard without accessing the shopper's device.

Payment security

Payment data handled by Shopify

No payment data stored by Leav

Leav does not store card numbers, bank account details, or payment credentials. All payment data flows directly between the shopper's device and Shopify Payments via Apple Pay or Google Pay. Leav receives only a confirmation token after payment is authorized.

PCI scope handled by Shopify

Because payment processing runs entirely through Shopify Payments and the device's wallet (Apple Pay / Google Pay), PCI scope is handled by Shopify and Apple/Google respectively. Leav sits outside the card data environment.

End-to-end encryption on all sessions

All Leav session data is transmitted over TLS 1.3. Scan frames used for exit verification are encrypted at rest and deleted after a configurable retention period (default 30 days).

Data handling summary
  • Card data: never stored by Leav
  • Scan frames: encrypted at rest, deleted after retention period
  • Session data: TLS 1.3 in transit
  • Payment tokens: Shopify Payments infrastructure
  • GDPR-compliant data residency for EU-based stores
Questions about data handling? Contact us or review our Privacy Policy.

Common concerns

Frequently asked questions

False positives are reviewed by staff at the exit point. When staff approve a flagged session, that data feeds back into the model. The system's false positive rate improves over time as it accumulates session history for your specific store and product set. All review decisions are logged for audit.

No. Leav does not require store-installed cameras. The exit verification layer uses the shopper's phone camera during the scan session and does not require overhead cameras or any hardware at the exit point beyond a Leav-connected tablet or staff device for exit scanning.

Sessions that complete payment but do not register an exit scan within a configurable window are flagged as unverified exits in the staff dashboard. Stores configure this timeout based on their typical visit length. The order is still captured in Shopify since payment already completed.

No. Leav does not use facial recognition, biometric identification, or any technology that identifies shoppers by appearance. The AI exit verification layer analyzes item count and product category patterns, not shopper identity. The only identity verification on a Leav session is the payment authorization, which is handled by Apple Pay or Google Pay.

Try it yourself

See the exit verification dashboard in a free trial.

Connect your Shopify store, run test sessions, and review flagged exits in the staff dashboard before you go live. 14 days free, no credit card.