If your site collects names, emails, phone numbers or orders, you are responsible for looking after that data. In Nigeria the NDPR sets expectations, and other laws apply if you serve customers elsewhere. This article is general guidance, not legal advice.
PRACTICAL MEASURES
Collect only what you actually need. Data you never collected cannot be leaked. Serve the whole site over HTTPS, not only the checkout. Never store card numbers or CVV codes. Use a hosted payment gateway. Restrict who can see customer records, and give each person their own login. Enable 2FA on all administrator accounts. Delete old data you no longer need, including exported CSV files sitting in a downloads folder. Keep export files out of public_html. An exported customer list in a web-reachable folder is a breach waiting to be found by a scanner. Keep backups encrypted or in access-controlled storage, since a backup contains everything the live database does.
PUBLISH A PRIVACY NOTICE
Say what you collect, why, how long you keep it, and how someone can ask for their data or its deletion.
IF A BREACH OCCURS
Contain it, assess what was exposed, open a ticket with us, take advice on notification obligations, and tell affected people honestly.