Skip to main content
Digital keys are valuable, so the platform is built to protect them at every step. This page explains, in plain terms, how keys are kept safe, how buyer links stay private, and how your store’s data is walled off from everyone else’s.

Keys are protected at rest

Your keys are stored in a protected form, not as plain readable text. They are not exposed as they move through the system, and they are masked in ordinary screens and lists. A real key value appears in only a few deliberate places:
  • When the buyer who bought it reveals it on their own delivery page.
  • When a teammate who can manage inventory clicks to reveal one key in your inventory screen. Each of these reveals is recorded in that key’s activity history.
  • In a delivery email, but only if you chose to put keys in your delivery template. By default the email carries a private link instead.
Most of your team never needs to see a raw key to run your store. Keep inventory Manage access to the people who need it, since those are the teammates who can reveal keys.
A buyer collects their keys through a private link. That link alone identifies their order, so there is no login for the buyer to manage. The link is long and unguessable, it is created only at delivery time, and it opens only on your store’s own web address, never on the admin app.
1

The link is unique and hard to guess

Each order gets its own private link that cannot be worked out from another one.
2

It only works in the right place

The link opens on your store’s surface and nowhere else, so it cannot be used against the admin app.
3

It reveals one order only

Holding the link shows just that buyer’s order, and keys stay masked until they choose to reveal them.

Each store’s data is separate

Every store’s data is kept apart from every other store’s. When you are signed in, you only ever see and touch data for the store you are currently in, and roles further limit what each teammate can reach inside that store. Invites are tied to the email address they were sent to, so only that person can use one to join your store.
This separation is enforced by the platform itself, not left to chance. Data is always tied to the store it belongs to, and requests are checked against both the store and the teammate’s permissions before anything is shown or changed.

Security guide

Practical steps to keep your store secure.

Accounts and roles

How permissions limit what teammates can do.

Stores and multi-tenancy

How each store’s data stays separate.

Delivery and custom domains

Where buyer delivery pages are hosted.