Published Last updated Written and reviewed by the Resale Intelligence team
On this page
Each store's data is kept apart in the database, customer IDs and IMEIs are encrypted, people see what their role allows and key changes are logged for good.
Your store's data belongs to your store. This page sums up how the system protects it; the technical detail is on Security.
Other stores can't see your data
Every row of store data carries your store's identifier, and the database has rules that only show rows of the store in use. Other stores therefore can't see your customers, items, purchase prices or profit. The only shared data is reference data such as the model catalog.
Data that identifies customers is encrypted
-
Customers' national ID numbers, dates of birth, phone numbers, emails and addresses are encrypted before they are saved.
-
Items' IMEI and serial numbers are encrypted too.
-
Searching by these numbers needs the full number, because the system compares a transformed value instead of reading the real number.
-
Customer names, customer codes and notes are stored normally so they can be searched. Don't write sensitive details in notes.
Each person sees what their job needs
-
Roles decide who sees what; for example a cashier doesn't see cost. See Store roles: what each can and cannot do.
-
ID and phone numbers are partly hidden. People with the permission can reveal them in full, and every reveal is recorded. See Reveal a customer's full ID and contact details.
-
Staff limited to some branches can't open other branches' documents. See Limit staff to certain branches.
Every important change is recorded
Financial documents can't be edited or deleted; a mistake is voided with a reason. The audit log keeps who did what, when and from which device, and the log itself can't be edited or deleted. See Audit log: who did what, and when.
Safer sign-in with 2FA
Accounts that reach money and customer data must use two-factor authentication. The system signs people out when they are inactive, and sensitive tasks ask for the password again. See Who must use 2FA and how long they have.
Backups and files
-
The database is backed up regularly with encryption, and restores are tested regularly.
-
Links that open files, such as item photos, are temporary and expire by themselves.
-
System logs don't keep customers' personal data.
What the store should do itself
-
Give everyone their own account; never share one.
-
Turn on 2FA for everyone and keep recovery codes safe.
-
Suspend the account of anyone who leaves, straight away. See Change roles, suspend or remove staff.
-
Review your team's access from time to time. See Review your team's access regularly.