Industry packs

Retail & E-commerce industry pack

Synthetic e-commerce orders, payments, shipments and returns with linked masking

Preview only · not activatable yet Version 2.0.0 · Complete

Everything on this page works without an account. Prefer a conversation? Request a demo (optional). Missing something? Request a feature.

This pack is installed and passes DataNivra’s pack conformance kit through the real engine, but it cannot be activated yet: no plan includes it yet, the standard agent image does not ship it, the control-plane catalogue does not list it and the hosted sandbox has no synthetic estate for it. You can explore its synthetic records, masking and scenarios on this page and in the browser demo. Tell us if you need it: demand decides which packs become activatable next.

Problems this pack solves

Masked data that still joins across 4 systems

6 cross-system relationships link fulfilment, loyalty, orders and storefront; the pack's masking keeps one pseudonym per identity on every side. For example, storefront.shoppers.shopper_id and orders.orders.shopper_ref get the same pseudonym.

The cases production samples rarely contain

8 ready-made scenarios generate them on demand, for example: A flash sale: many app orders and payments within a two-hour window; carts left without checkout; partially returned orders with refunds and free-text return comments.

Sensitive fields found and masked before anyone sees them

40 columns across 12 entities are classified (direct identifier, financial, payment, PII, quasi identifier and sensitive) and covered by 3 masking templates you review and approve.

Evidence that each dataset is fit to use

2 certification presets check masking coverage, referential integrity, orphans and row counts before a dataset can be provisioned; a failed dataset is never provisioned.

Entities and relationships

12 entities across 4 source systems, generated from the pack’s own entity model.

Entity graph of the Retail & E-commerce pack12 entities in 4 systems (storefront, orders, fulfilment, loyalty) linked by 16 relationships, 6 of them across systems. The table after the graph lists every relationship.storefrontordersfulfilmentloyaltyShopper (storefront.shoppers)Shopperstorefront.shoppersShopperAddress (storefront.shopper_addresses)ShopperAddressstorefront.shopper_add…Product (storefront.products)Productstorefront.productsCart (storefront.carts)Cartstorefront.cartsCartItem (storefront.cart_items)CartItemstorefront.cart_itemsReview (storefront.reviews)Reviewstorefront.reviewsOrder (orders.orders)Orderorders.ordersOrderLine (orders.order_lines)OrderLineorders.order_linesPayment (orders.payments)Paymentorders.paymentsReturn (orders.returns)Returnorders.returnsShipment (fulfilment.shipments)Shipmentfulfilment.shipmentsLoyaltyAccount (loyalty.loyalty_accounts)LoyaltyAccountloyalty.loyalty_accoun…
Arrows point from the referencing entity to the one it references. Solid: a foreign key inside one system. Dashed: a cross-system relationship — the pack keeps the same pseudonym on both sides, so masked data still joins.
All 16 relationships as a table
Relationships of the Retail & E-commerce pack
EntityReferencesColumnsKind
ShopperAddressShoppershopper_id → shopper_idWithin a system
CartShoppershopper_id → shopper_idWithin a system
CartItemCartcart_id → cart_idWithin a system
CartItemProductproduct_sku → product_skuWithin a system
ReviewShoppershopper_id → shopper_idWithin a system
ReviewProductproduct_sku → product_skuWithin a system
OrderLineOrderorder_number → order_numberWithin a system
PaymentOrderorder_number → order_numberWithin a system
ReturnOrderorder_number → order_numberWithin a system
OrderShoppershopper_ref → shopper_idAcross systems (pack relationship template)
OrderShopperAddressshipping_location_ref → location_idAcross systems (pack relationship template)
OrderCartcart_ref → cart_idAcross systems (pack relationship template)
OrderLineProductproduct_sku → product_skuAcross systems (pack relationship template)
ReturnOrderLineline_ref → line_idWithin a system (pack relationship template)
ShipmentOrderorder_ref → order_numberAcross systems (pack relationship template)
LoyaltyAccountShoppershopper_ref → shopper_idAcross systems (pack relationship template)

Realistic synthetic records

Synthetic data. Every record on this page is synthetic, generated from a fixed seed by the pack's own generator; masked values come from the real masking engine.

Shopper — storefront.shoppers (synthetic)
shopper_id sensitivegiven_name sensitivefamily_name sensitiveemail sensitivephone sensitivebirth_date sensitivelast_ip_address sensitivemarketing_opt_insigned_up_at
SHP000000001TamoKestshawtamo.hollofield2048@example.com555-048-9920—198.51.100.95false2021-01-08T08:52:44
SHP000000002SelanVallridgeselan.holloridge8135@example.org555-035-4981—198.51.100.114true2020-08-03T00:02:13

Masking: before and after

Template Linked e-commerce test data (RET_LINKED_TEST_DATA) applied to a synthetic Shopper record from storefront.shoppers.

Synthetic Shopper record before and after masking
ColumnClassified asBefore (synthetic)After masking
shopper_idDirect identifierSHP000000001SHP098977906
given_namePII, Direct identifierTamoMarira
family_namePII, Direct identifierKestshawCaldfield
emailPII, Direct identifiertamo.hollofield2048@example.comselric.yarrholt4319@example.org
phonePII, Direct identifier555-048-9920555-011-0834
birth_datePII, Quasi identifier—— (same value after masking)
last_ip_addressPII, Quasi identifier198.51.100.95009.17.346.24

Same pseudonym in two systems. The identifier SHP000000001 appears in storefront.shoppers.shopper_id and in orders.orders.shopper_ref. Both become SHP098977906, so the masked systems still join (relationship RET_ORDER_SHOPPER).

Masked with a fixed public sample key so this example is reproducible; your data is masked with your own key, referenced from your secret store.

Synthetic scenarios you can run

10 runnable scenarios. Preview them in your browser without an account; the hosted sandbox opens when the pack becomes activatable.

Everyday shopping

Normal RET_EVERYDAY_SHOPPING

Ordinary shoppers, carts, orders, payments, deliveries and loyalty accounts

Everyday, valid records: the baseline most tests expect. Children per parent record: 1–3.

Preview in the browser demo: Everyday shopping

Flash sale peak

Rare RET_FLASH_SALE_PEAK

A flash sale: many app orders and payments within a two-hour window

Valid but uncommon business situations that production samples often miss. Children per parent record: 2–5.

Preview in the browser demo: Flash sale peak

Returns and refunds

Rare RET_RETURNS_AND_REFUNDS

Partially returned orders with refunds and free-text return comments

Valid but uncommon business situations that production samples often miss. Children per parent record: 1–3.

Preview in the browser demo: Returns and refunds

Payment declines

Rare RET_PAYMENT_DECLINES

Declined card payments, each with a decline reason

Valid but uncommon business situations that production samples often miss. Children per parent record: 1–3.

Preview in the browser demo: Payment declines

Split shipments

Rare RET_SPLIT_SHIPMENTS

Orders shipped in several parcels, some of which fail delivery

Valid but uncommon business situations that production samples often miss. Children per parent record: 2–4.

Preview in the browser demo: Split shipments

Long reviews

Rare RET_LONG_REVIEWS

Reviews with long free text (synthetic) to exercise free-text detection and redaction

Valid but uncommon business situations that production samples often miss. Children per parent record: 1–3.

Preview in the browser demo: Long reviews

Promo abuse review

Rare RET_PROMO_ABUSE_REVIEW

Orders flagged for promotion-abuse review (a flag only, not a finding)

Valid but uncommon business situations that production samples often miss. Children per parent record: 1–2.

Preview in the browser demo: Promo abuse review

Large orders

Boundary RET_LARGE_ORDERS

Order totals at or above the large-order threshold (exactly at it for every tenth row)

Values at the edges of valid ranges (limits, thresholds, extremes). Children per parent record: 1–2.

Preview in the browser demo: Large orders

Duplicate orders

Duplicate RET_DUPLICATE_ORDERS

Orders submitted twice with identical content under new order numbers

Records that repeat others under new keys (clean-up and matching tests). Children per parent record: 2–4.

Preview in the browser demo: Duplicate orders

Negative tests, kept apart. This scenario produces deliberately broken data for error handling and never passes certification as valid data:

  • RET_BROKEN_REFERENCES — Dangling cross-system references and invalid values for error-handling tests

Sample schemas and representative outputs

The schema the pack expects in each system (also as CREATE TABLE DDL in the downloads). A run produces a masked or synthetic dataset with the same tables, a certification report with the gates of the chosen preset, and an evidence manifest with checksums — the rows stay in your environment.

Shopper — storefront.shoppers · 9 columns

A registered shopper account (the natural subset root).

ColumnTypeRequiredSensitive classes
shopper_id (key)VARCHAR(12)YesDirect identifier
given_nameVARCHAR(64)YesPII, Direct identifier
family_nameVARCHAR(64)YesPII, Direct identifier
emailVARCHAR(128)NoPII, Direct identifier
phoneVARCHAR(32)NoPII, Direct identifier
birth_dateDATENoPII, Quasi identifier
last_ip_addressVARCHAR(45)NoPII, Quasi identifier
marketing_opt_inBOOLEANYes—
signed_up_atTIMESTAMPYes—
ShopperAddress — storefront.shopper_addresses · 8 columns

A saved shipping or billing address of a shopper.

ColumnTypeRequiredSensitive classes
location_id (key)BIGINTYes—
shopper_idVARCHAR(12)YesDirect identifier
usage_typeVARCHAR(10)Yes—
recipient_nameVARCHAR(96)YesPII, Direct identifier
street_addressVARCHAR(128)YesPII, Quasi identifier
cityVARCHAR(64)YesQuasi identifier
postal_codeVARCHAR(10)NoPII, Quasi identifier
country_codeVARCHAR(2)Yes—
Product — storefront.products · 5 columns

A catalogue product (reference data; invented names).

ColumnTypeRequiredSensitive classes
product_sku (key)VARCHAR(12)Yes—
product_nameVARCHAR(64)Yes—
categoryVARCHAR(16)Yes—
unit_priceDECIMAL(10,2)Yes—
activeBOOLEANYes—
Cart — storefront.carts · 6 columns

A shopping cart of one session; converted carts become orders.

ColumnTypeRequiredSensitive classes
cart_id (key)BIGINTYes—
shopper_idVARCHAR(12)YesDirect identifier
device_idVARCHAR(24)NoPII, Quasi identifier
channelVARCHAR(4)Yes—
statusVARCHAR(10)Yes—
created_atTIMESTAMPYes—
CartItem — storefront.cart_items · 5 columns

A product placed in a cart.

ColumnTypeRequiredSensitive classes
cart_item_id (key)BIGINTYes—
cart_idBIGINTYes—
product_skuVARCHAR(12)Yes—
quantityINTYes—
added_atTIMESTAMPYes—
Review — storefront.reviews · 7 columns

A product review; its free text can contain personal data.

ColumnTypeRequiredSensitive classes
review_id (key)BIGINTYes—
shopper_idVARCHAR(12)YesDirect identifier
product_skuVARCHAR(12)Yes—
ratingINTYes—
reviewer_display_nameVARCHAR(64)NoPII, Direct identifier
review_textVARCHAR(2000)NoPII, Sensitive
posted_atTIMESTAMPYes—
Order — orders.orders · 11 columns

An order placed from a converted cart and shipped to one of the shopper's addresses.

ColumnTypeRequiredSensitive classes
order_number (key)VARCHAR(12)YesDirect identifier
shopper_refVARCHAR(12)YesDirect identifier
cart_refBIGINTYes—
shipping_location_refBIGINTYes—
channelVARCHAR(4)Yes—
statusVARCHAR(20)Yes—
order_totalDECIMAL(12,2)YesFinancial
currency_codeVARCHAR(3)Yes—
promo_codeVARCHAR(16)No—
promo_abuse_flagBOOLEANYes—
placed_atTIMESTAMPYes—
OrderLine — orders.order_lines · 6 columns

One product line of an order.

ColumnTypeRequiredSensitive classes
line_id (key)BIGINTYes—
order_numberVARCHAR(12)YesDirect identifier
product_skuVARCHAR(12)Yes—
quantityINTYes—
unit_priceDECIMAL(10,2)Yes—
line_totalDECIMAL(12,2)Yes—
Payment — orders.payments · 11 columns

A payment attempt for an order (card, wallet or bank transfer).

ColumnTypeRequiredSensitive classes
payment_id (key)BIGINTYes—
order_numberVARCHAR(12)YesDirect identifier
methodVARCHAR(14)Yes—
card_numberVARCHAR(19)NoPayment, Direct identifier
card_expiryVARCHAR(5)NoPayment
cardholder_nameVARCHAR(96)NoPII, Direct identifier
wallet_ibanVARCHAR(34)NoFinancial, Direct identifier
amountDECIMAL(12,2)YesFinancial
statusVARCHAR(12)Yes—
decline_reasonVARCHAR(24)No—
attempted_atTIMESTAMPYes—
Return — orders.returns · 9 columns

A return and refund of one order line.

ColumnTypeRequiredSensitive classes
return_id (key)BIGINTYes—
order_numberVARCHAR(12)YesDirect identifier
line_refBIGINTYes—
reasonVARCHAR(20)Yes—
statusVARCHAR(10)Yes—
refund_amountDECIMAL(12,2)YesFinancial
refund_referenceVARCHAR(20)YesFinancial, Direct identifier
customer_commentVARCHAR(400)NoPII, Sensitive
requested_atTIMESTAMPYes—
Shipment — fulfilment.shipments · 12 columns

A parcel of an order (split orders have several), with its delivery address.

ColumnTypeRequiredSensitive classes
shipment_id (key)BIGINTYes—
order_refVARCHAR(12)YesDirect identifier
parcel_indexINTYes—
tracking_numberVARCHAR(20)YesDirect identifier
carrierVARCHAR(20)Yes—
recipient_nameVARCHAR(96)YesPII, Direct identifier
delivery_streetVARCHAR(128)YesPII, Quasi identifier
delivery_cityVARCHAR(64)YesQuasi identifier
delivery_postal_codeVARCHAR(10)NoPII, Quasi identifier
statusVARCHAR(16)Yes—
shipped_atTIMESTAMPYes—
delivered_atTIMESTAMPNo—
LoyaltyAccount — loyalty.loyalty_accounts · 5 columns

A loyalty programme membership with a points balance.

ColumnTypeRequiredSensitive classes
loyalty_id (key)VARCHAR(12)YesDirect identifier
shopper_refVARCHAR(12)YesDirect identifier
tierVARCHAR(8)Yes—
points_balanceINTYesFinancial
enrolled_onDATEYes—

Compatible connectors

Verified with this pack version: PostgreSQL and Local files (Parquet / CSV). 17 more connectors are compatible by capability: they support what the pack needs, but have not been verified with this pack yet.

ConnectorStatus with Retail & E-commerce
Local files (Parquet / CSV)Verified with this pack
PostgreSQLVerified with this pack
Amazon S3 / S3-compatible storageCompatible by capability (not yet verified with this pack)
Apache Kafka (connector in preview)Compatible by capability (not yet verified with this pack)
Azure Blob Storage / Data Lake StorageCompatible by capability (not yet verified with this pack)
DatabricksCompatible by capability (not yet verified with this pack)
Generic SQL (SQLAlchemy)Compatible by capability (not yet verified with this pack)
Google BigQueryCompatible by capability (not yet verified with this pack)
HTTP APIs (connector in preview)Compatible by capability (not yet verified with this pack)
IBM Db2 (connector in preview)Compatible by capability (not yet verified with this pack)
Mainframe files (EBCDIC / copybook) (connector in preview)Compatible by capability (not yet verified with this pack)
MariaDBCompatible by capability (not yet verified with this pack)
Microsoft SQL ServerCompatible by capability (not yet verified with this pack)
MongoDB (connector in preview)Compatible by capability (not yet verified with this pack)
MySQLCompatible by capability (not yet verified with this pack)
Oracle DatabaseCompatible by capability (not yet verified with this pack)
Parquet filesCompatible by capability (not yet verified with this pack)
SnowflakeCompatible by capability (not yet verified with this pack)
SQLite (developer evaluation) (connector in preview)Compatible by capability (not yet verified with this pack)

Prerequisites and expected setup effort

You need

  • This pack is not in any plan yet.
  • One DataNivra agent inside your network (outbound HTTPS only) that ships Retail & E-commerce 2.0.0.
  • Read-only access to a compatible source (verified with this pack: PostgreSQL, Local files (Parquet / CSV)).
  • A non-production target environment the agent may write test data to.
  • A masking key in your own secret store, referenced as vault://…, azure-kv://… or env://… (DataNivra only ever sees the reference).
  • For production sources, a second person who approves policies (separation of duties).

A DataNivra agent that reports its installed industry packs (releases after agent 0.3.0); the control plane runs a pack job only on an agent holding the exact active pack version with the catalogued integrity digest.

Expected setup effort (estimates)

StepEstimate
Try the synthetic sandbox
No install: sign up and open the sandbox.
Minutes (estimate)
Install (or reuse) the agent
One Docker command or a Helm chart; outbound HTTPS only.
Under an hour (estimate)
Connect a source
Register a read-only source through the existing connector workflow.
Under an hour (estimate)
Review and approve policies
Create drafts from the Retail & E-commerce templates, review and approve them.
Under an hour (estimate)
First certified dataset
Run the first job; certification and evidence are produced automatically.
Minutes (estimate)

Certification presets in plain language

RET_STRICT

Every gate; full masking coverage; zero orphaned carts, orders, payments, returns, shipments or loyalty accounts; exact row counts. Default for masked e-commerce test data.

  • Masking coverage of at least 100% of sensitive columns
  • No orphaned child records
  • Empty-value ratio may rise by at most 5%
  • Row counts must match exactly
16 gates it requires
  • POLICY_COVERAGE: every sensitive column is covered by an approved policy
  • MASKING_COMPLETION: masking finished on every covered column
  • REFERENTIAL_INTEGRITY: every reference still points at an existing record
  • SCHEMA_VALIDATION: the output schema matches the source schema
  • DATA_QUALITY: empty-value ratios stay within the preset’s drift limit
  • ROW_COUNT_RECONCILIATION: row counts match the plan within the tolerance
  • ORPHAN_DETECTION: no child record lost its parent
  • PROVENANCE: every row is tagged masked or synthetic
  • MANIFEST: a manifest lists every output table with checksums
  • POLICY_VERSION: the exact approved policy versions are recorded
  • ENGINE_VERSION: the engine version is recorded
  • CHECKSUMS: output checksums are recorded for later verification
  • IDENTITY_CONSISTENCY: linked identifiers got the same pseudonym in every system
  • SOURCE_READ_ONLY: the source was only read, never written
  • EGRESS_GUARD: no row-level data left the agent
  • CONNECTOR_HEALTH: the connectors stayed healthy during the run

RET_SCENARIO_TESTING

Every gate, with slightly relaxed NULL-ratio drift for scenario datasets whose business states (abandoned carts, declined payments, undelivered parcels) leave optional fields empty.

  • Masking coverage of at least 100% of sensitive columns
  • No orphaned child records
  • Empty-value ratio may rise by at most 15%
  • Row counts must match exactly
16 gates it requires
  • POLICY_COVERAGE: every sensitive column is covered by an approved policy
  • MASKING_COMPLETION: masking finished on every covered column
  • REFERENTIAL_INTEGRITY: every reference still points at an existing record
  • SCHEMA_VALIDATION: the output schema matches the source schema
  • DATA_QUALITY: empty-value ratios stay within the preset’s drift limit
  • ROW_COUNT_RECONCILIATION: row counts match the plan within the tolerance
  • ORPHAN_DETECTION: no child record lost its parent
  • PROVENANCE: every row is tagged masked or synthetic
  • MANIFEST: a manifest lists every output table with checksums
  • POLICY_VERSION: the exact approved policy versions are recorded
  • ENGINE_VERSION: the engine version is recorded
  • CHECKSUMS: output checksums are recorded for later verification
  • IDENTITY_CONSISTENCY: linked identifiers got the same pseudonym in every system
  • SOURCE_READ_ONLY: the source was only read, never written
  • EGRESS_GUARD: no row-level data left the agent
  • CONNECTOR_HEALTH: the connectors stayed healthy during the run

Activation status

What is missing before you can activate the Retail & E-commerce pack yourself:

  • no plan includes it yet
  • the standard agent image does not ship it
  • the control-plane catalogue does not list it
  • the hosted sandbox has no synthetic estate for it

Until then, preview it in the browser demo and download its synthetic asset bundle below.

Tell us you need the Retail & E-commerce pack or request a feature for it.

Downloads

Version 2.0.0, 67 files (193.5 KB), all synthetic and generated from the pack itself. Every file’s SHA-256 is listed in MANIFEST.json.

Start here (2)
Entity–relationship diagram (2)
Sample schemas (5)
Policy templates (9)
API, CLI, SDK and CI/CD examples (10)
Synthetic sample data (CSV, JSON, Parquet) (37)

Troubleshooting

The reason codes you can meet on the way, with the recovery step. Every code is also in the error-code catalog.

SANDBOX_PACK_NOT_OFFERED — Synthetic estate not offered
A requested synthetic estate (industry pack) is not available in the hosted sandbox. What to do: Start the sandbox with the default estates.
ENTITLEMENT_REQUIRED — Plan does not include this
Your plan does not include this feature or industry pack. What to do: Upgrade in Billing & Plan.
PACK_INTEGRITY_UNVERIFIED — Pack integrity not verified
This pack version was registered without an integrity digest, so it cannot be activated (fail closed). What to do: Ask your operator to re-register the pack catalogue with the current control-plane image (register-pack), then activate again.
PACK_DEPENDENCY_INACTIVE — Required pack not active
This pack depends on another industry pack that is not active for your organization. What to do: Activate the packs this pack depends on first, then activate it again.
AGENT_PACK_MISSING — No agent can run this industry pack
The job's agent does not report the pack (older agents report no packs at all), so the job was not sent. What to do: Upgrade the agent to a release that reports its installed packs and ships this pack, then run the request again.
AGENT_PACK_VERSION_INCOMPATIBLE — Industry pack version differs on the agent
The agent holds a different version of the pack than the one the job was approved for. What to do: Deploy an agent with the pack's active version, or roll the pack back in Industry packs.
AGENT_PACK_INTEGRITY_MISMATCH — Agent pack differs from the catalogue
The agent reports the pack's version with a different integrity digest than the catalogued one, so the job was not sent. What to do: Redeploy the agent from the official signed image for this release, then run the request again.
PACK_TEMPLATES_UNAVAILABLE — Pack templates not registered
This pack version was registered without its policy templates. What to do: Ask your operator to re-register the pack catalogue (register-pack); create policies manually meanwhile.
PACK_TEMPLATE_KEY_REF_REQUIRED — Masking key reference required
A selected template keeps identities linked across systems and needs your masking key reference. What to do: Provide key_ref, e.g. vault://your-vault/tdm-masking-key, then create the drafts again.
PACK_NOT_ENABLED — Industry pack not enabled
The industry pack is not enabled for this tenant. What to do: Enable the pack (if your plan includes it).

Frequently asked questions

Are the Retail & E-commerce records on this page real?
No. Every record on this page is synthetic, generated from a fixed seed by the pack's own generator; masked values come from the real masking engine. The masking example uses a fixed public sample key; your own data is masked with a key from your secret store.
Can I activate the Retail & E-commerce pack myself?
This pack is installed and passes DataNivra’s pack conformance kit through the real engine, but it cannot be activated yet: no plan includes it yet, the standard agent image does not ship it, the control-plane catalogue does not list it and the hosted sandbox has no synthetic estate for it. You can explore its synthetic records, masking and scenarios on this page and in the browser demo. Tell us if you need it: demand decides which packs become activatable next.
Which databases and files does the Retail & E-commerce pack work with?
Verified with this pack version: PostgreSQL and Local files (Parquet / CSV). 17 more connectors are compatible by capability: they support what the pack needs, but have not been verified with this pack yet.
How long does a first certified Retail & E-commerce dataset take?
Estimates, not guarantees — try the synthetic sandbox: minutes; install (or reuse) the agent: under an hour; connect a source: under an hour; review and approve policies: under an hour; first certified dataset: minutes.
Which test scenarios does the Retail & E-commerce pack include?
10 runnable scenarios (everyday shopping, flash sale peak, abandoned carts, returns and refunds and more), plus 1 negative-test scenario kept apart from valid data.
Do Retail & E-commerce rows leave my network?
No. The DataNivra agent runs inside your environment: it reads the source, masks, subsets, generates and certifies there, and sends only metadata, aggregate counts and evidence to the DataNivra control plane (customer-resident processing, zero raw-production-data egress).

Learn the concepts, then come back to activate

Regulatory context

The Retail & E-commerce pack supports privacy and data-minimisation practices by keeping personal data inside your environment; it does not, by itself, establish compliance with any law or regulation.

Everything on this page works without an account. Prefer a conversation? Request a demo (optional). Missing something? Request a feature.