Security & your data

Before you hand over the keys.

Moving your inventory and your customer list onto somebody else's software is a real decision. Here's what we store, where it sits, who can open it, and the things we don't have yet.

Last updated: September 2026 · By Foil Haven · support@foilhaven.com

What we hold

What Foil Haven stores for your shop

Only what you put in, or what the Shopify store you connect sends us.

  1. Inventory

    Each card you stock, with its condition, finish, what you paid, what you listed it at, and what it sold for. Sealed product and supplies too.

  2. Sales

    Counter sales, refunds, and trade-ins: what sold, the tender type, tax, and discounts.

  3. Customers

    Whatever you enter for a customer: a name, and if you add them, an email, a phone number, and notes. Marketing opt-in is off unless you turn it on.

  4. Store credit and gift cards

    Balances and the history behind them, tied to the customer who holds them.

  5. Buylists and requests

    Buylist submissions, deck-list orders, and event sign-ups, with the contact details the customer gave.

  6. Your team

    Login emails for you and any staff you invite, and which of them is an owner.

  7. Shopify, if you connect it

    The products, stock, and orders Shopify sends us, plus an access token that lets us update your listings. The token is encrypted before it's saved.

What we never hold: payment card numbers. Not yours, not your customers'.

Where it lives

Where is my store's data kept?

Your data sits in a Postgres database run by Supabase, in Amazon's us-east-1 region in the United States. The app and this site are hosted on Vercel. Every connection is HTTPS; plain HTTP gets redirected.

Your browser never talks to the database directly. Row-level security is switched on for every table in the schema, and the tables holding customers, store credit, and buylists have all browser-level access revoked outright. Reads and writes go through our server, which works out your store from your verified login every time rather than trusting what the page sends.

The stack

The app
Vercel — app.foilhaven.com
This site
Vercel — foilhaven.com
Database
Supabase Postgres 17 — AWS us-east-1
Logins
Supabase Auth
Subscriptions
Stripe
Email
SendGrid
Backups
Private GitHub repository, encrypted
Connection
HTTPS only

Who can see it

Who can see my inventory and customers?

Your account has two kinds of people. Owners see everything. Staff can run the register, work intake, and look up a customer at the counter, but they can't reach the dashboard, your costs and margins, billing, settings, the staff list, or exports. Staff who try get sent back to intake.

Then there's me. Foil Haven is one person, and I have administrator access to the production database and the hosting. That's how I fix things when you email about a problem. There's no special support mode in the app, and nothing currently logs when I open your data. I'd rather tell you that here than have you find out later.

Payments

How do payments work?

  1. Your subscription: you pay on Stripe's own checkout page and manage the card in Stripe's billing portal. Your card number goes to Stripe, not to us.
  2. When Stripe tells us a payment went through or failed, the message is checked against Stripe's signature before we act on it. Unsigned or forged messages are rejected.
  3. At your counter, the POS takes cash, store credit, gift cards, and splits between them. It doesn't charge cards. You keep running card sales on your own terminal, so those card numbers never pass through Foil Haven either.

Shopify works the same way. We connect through Shopify's own sign-in and approval screen, and every order message from Shopify has its signature checked before we accept it.

Your data is yours

Can I take my data with me?

Yes. From the dashboard, any owner can download the whole inventory as a CSV: SKU, game, card name, set, condition, finish, buy price, status, sold price, and date acquired. It works on every plan, including the free one, and there's no need to ask first.

Customer records and sales history don't have an export button yet. Email me and I'll send them. Cancelling a paid plan marks the subscription cancelled and leaves your data alone. Disconnecting Shopify deletes the access token right away. If you also uninstall the app, Shopify asks us 48 hours later to scrub the order data it sent, and we do. Your own inventory and customer records stay put either way.

Backups

Is my data backed up?

Every night the whole database is dumped, encrypted with AES-256, and stored away from Supabase in a private GitHub repository. The same job then downloads that copy back, decrypts it, and checks that it opens and isn't an empty shell. Only after that check passes does it remove an older backup, so a bad night can't push out a good copy.

The last 14 nightly copies are kept, plus one from each of the last 8 Sundays. If the job fails, I get an email.

The honest part

What we don't have yet

If your insurer, bank, or partner needs one of these, Foil Haven can't give it to you today.

  • No SOC 2 report, and no other security certification.
  • No third-party penetration test.
  • Foil Haven is one person. There's no security team and no on-call rotation.
  • No two-factor login yet. Accounts use an email and a password of at least 8 characters.
  • No log that records when I open a store's data for support.
  • Customer lists and sales history don't have a self-serve export yet.
  • Nobody has rehearsed a full restore of a backup into a fresh database.
  • No status page and no uptime guarantee.

Questions store owners ask

Does Foil Haven ever see my customers' card numbers?

No. When you subscribe, you pay on a checkout page Stripe hosts, and card details go to Stripe. At the counter, the Foil Haven POS doesn't charge cards at all: it takes cash, store credit, and gift cards, and you keep running card sales on your own terminal.

Can my staff see what I paid for cards?

No. Staff accounts can ring sales and work intake, but the dashboard, margins, cost basis, billing, settings, staff management, and exports are owner-only. The server checks your role on every one of those requests, and staff get sent back to intake.

Can another store see my inventory or customers?

No. Every request looks up which store you belong to from your verified login and scopes the query to that store. A store ID sent from the browser is ignored unless your account actually belongs to that store.

Can I get my inventory out if I leave?

Yes. Any owner can download the full inventory as a CSV from the dashboard, on any plan, including the free one. For customer records and sales history there's no export button yet, so email me and I'll send them to you.

How long do you keep my data after I cancel?

Cancelling a paid plan doesn't delete anything; you drop to the free plan and your data stays where it is. If you close your account, your data is deleted from our live systems within 30 days and ages out of our encrypted backups within 90 days. That's in the privacy policy.

Will you tell me if there's a breach?

Yes. If we confirm a breach affecting your store's data, we tell you within 72 hours of confirming it. That's in the privacy policy.

What happens if the database is lost?

A backup runs every night. It's encrypted, stored away from Supabase in a private GitHub repository, then downloaded again and checked before any older copy is removed. Because it's nightly, restoring from it could lose up to a day of changes. I haven't yet rehearsed a full restore into a fresh database, and that's on the list below.

Who at Foil Haven can look at my data?

Me, Richard, and nobody else, because there isn't anybody else. I have administrator access to the production database and hosting, which is how I fix things when you report a problem. There's no support mode in the app and no log of when I look, which is why it's listed under what we don't have yet.

Last updated: September 2026 · By Foil Haven

Got a question this page doesn't answer?

Email it to me. If the answer is “we don't have that yet,” you'll hear that too. The legal version lives in the privacy policy, and who builds this is on the about page.