Skip to content
TH Start free trial

Data security

What the system does to protect your store's data and your customers' data, described as it actually works.

Published Last updated Written and reviewed by the Resale Intelligence team

On this page
  1. Each shop's data is separated in the database
  2. Customer and device data is encrypted
  3. Accounts and signing in
  4. An audit trail that can't be changed
  5. Access by our team
  6. Backup and restore
  7. No personal data in system logs
  8. In your browser
  9. Checked at every release
  10. PDPA
  11. Report a security issue

In short: each store's data is separated in the database, customers' sensitive data is encrypted, accounts with wide access must use two-factor authentication, every important action is logged in a record that can't be changed, and backups are encrypted and restore-tested every month.

Each shop's data is separated in the database

Every row belongs to a store, and the database enforces a second layer of separation (forced Row-Level Security). The database account the app uses has no right to bypass it, so even if the app's code had a bug, the database would not return another store's data.

Customer and device data is encrypted

  • Customers' national ID numbers, dates of birth, phone numbers, email addresses and addresses, and devices' IMEI and serial numbers, are encrypted with AES-256 in the database.
  • Exact-match search works through a hash index with its own key, separate from the encryption key, so nothing has to be decrypted to search.
  • Screens show this data masked. Viewing the full value requires permission and is logged.
  • ID card photos and documents are stored privately and open only through signed links that expire after 10 minutes.
  • Names, phone numbers and email addresses entered in the website's forms are encrypted too.
  • All connections use HTTPS.

Accounts and signing in

  • Two-factor authentication (2FA) is required for Owner, Store Admin and for our own team, and a store can require it for everyone.
  • Passwords are at least 10 characters long and include lower-case and upper-case letters and numbers. They must also not appear in known password breaches (checked with a partial hash; the password itself is never sent).
  • Attempts are rate-limited, never locked out: 5 sign-in attempts per minute per email address and network, and at most 30 per hour per account from anywhere; 5 2FA codes per minute, 20 per hour and 50 per day.
  • Sign-up, password reset requests and password resets: 5 per minute and 20 per hour per network, and at most 5 reset emails per hour to one address.
  • You can see your signed-in devices and sign any of them out. Changing your password signs out every other device, and resetting it by email signs out every device.
  • "Remember me" lasts at most 30 days, and ends when you sign out other devices or change your password.
  • 13 roles with their own permissions, and store owners can adjust permissions person by person.

An audit trail that can't be changed

Every important change is logged with who did it, when, from where, and the values before and after. The database refuses to change or delete these entries. Financial transactions can't be deleted or edited; they are corrected by voiding them with a reason and a reversing entry.

Access by our team

Our team's back office shows only store-level information (store name, plan, number of users and branches). It has no screens for viewing a store's customers, stock or transactions. Any change to a store's status by our team must state a reason and is logged.

  • Everyone on our team must use two-factor authentication before entering the back office.
  • Legal rules and rates the system uses must be checked and verified by a second administrator before use. The author can't verify their own rule, and a verified rule can't be changed.

Backup and restore

The database is backed up every day and encrypted with AES-256, with changes archived continuously so it can be restored to a chosen moment (point-in-time recovery). We run a real restore test every month, not just a check that the backup succeeded.

No personal data in system logs

Application logs and error reports strip passwords, ID numbers, phone numbers, email addresses, addresses and IMEIs before they are written, and identify users by ID only. Access logs keep no query strings, and failed sign-ins store the email address only as a hash.

In your browser

  • A Content Security Policy with a new nonce on every request, so scripts that don't come from us can't run.
  • Our pages can't be embedded in other websites (clickjacking protection), and HTTPS is enforced with HSTS.
  • No third-party scripts or fonts.
  • 5 cookies, all of them necessary, with no analytics or advertising cookies. Sign-in cookies can't be read by scripts (HttpOnly) and are sent over HTTPS only. See the cookie list

  • Signed-in pages are never kept in the browser's cache, so pressing Back on a shared device doesn't bring store data back.

Checked at every release

Before every release, automated tests run, including tests that one store can't see another store's data, along with static code analysis, a check for libraries with known vulnerabilities, a container image scan, an OWASP ZAP scan of the website, and a backup and restore test. Releases go out automatically only when all of them pass.

PDPA

  • Store customers' consents are recorded per purpose, and the record is append-only: it can't be changed afterwards.
  • Store owners can export all of their store's data themselves, on every plan.
  • Data is erased or anonymised on request, keeping only what the law requires us to keep.
  • A personal data breach process: we assess the risk and notify the Office of the Personal Data Protection Committee within 72 hours of becoming aware, unless the breach is unlikely to put people's rights at risk.

Details are in our Privacy policy

Report a security issue

If you find a vulnerability, please report it via our contact page — see security.txt

See true profit from the first unit you buy

Try every feature free for 14 days, no card needed. Move your stock over from Excel yourself.