Trust and security
What we do with your data
These are our own commitments as the operator of this platform, written plainly. Where we have not yet done something, we say so rather than implying otherwise.
What we collect
Account email, any display name you set, order records, and the messages you send us through forms on this site.
Access control
Customer data sits behind row-level security: a signed-in account can read its own orders and credit ledger and nothing else. Roles are stored separately from profiles.
Credentials
The browser never receives a privileged database credential. Privileged operations run server-side after the caller has been authenticated and authorised.
Payment data
We do not store card numbers on our own infrastructure.
Retention
Order and ledger records are retained while your account is open, because they are the basis of your credit balance. Contact-form messages are kept until the enquiry is closed.
Reporting a vulnerability
Write to us through the contact form with steps to reproduce. We will confirm receipt and will not pursue good-faith researchers.
What we do not claim
We hold no third-party security certification at this time and make no compliance claims we cannot evidence. If a certification or audit is completed, it will be named here with its scope and date, not implied by a badge.