Your team, roles & security
Two kinds of login
- Operators (PIN): everyone on the floor gets a name and a 6-digit PIN. Fast to type between parcels, no emails or passwords to manage. Any team member can also get an email sign-in (set it on the Team page): they set their own password through a link, sign in with the email on their own device, and land signed in as themselves — same role, same name on every action. Handy for people who work from a laptop or phone rather than a shared station.
- PIN sign-in is optional per brand: if everyone works on their own device, switch PINs off entirely (Settings → Security → "How your team signs in") — the team then signs in with email + password only. The switch refuses to turn off while anyone would be locked out.
- The founder (email + password): the owner account, used for settings, credentials and team management. Creating it is part of onboarding, and the email must be verified before the workspace can connect stores or sync customer data.
Roles: who sees and does what
| Ops | Support | Manager | Admin | |
|---|---|---|---|---|
| Work the queue, pack, scan | ✅ | ✅ | ✅ | ✅ |
| Confirm / hold / cancel orders | ✅ | ✅ | ✅ | |
| Fix addresses & personalisation | ✅ | ✅ | ✅ | |
| Edit stock manually | ✅ | ✅ | ✅ | |
| Change an order note (writes to Shopify) | ✅ | ✅ | ✅ | |
| Create a return or replacement | ✅ | ✅ | ✅ | |
| Log a payment received | ✅ | ✅ | ||
| Record a refund on a return | ✅ | ✅ | ||
| Reverse a packed order (with reason) | ✅ | ✅ | ||
| Override the inventory gate (with reason) | ✅ | ✅ | ||
| Release/cancel a claimed pick list (with reason) | ✅ | ✅ | ||
| Close dispatch with discrepancies (with reason) | ✅ | ✅ | ||
| Team, PINs, settings, credentials | ✅ |
Powerful actions always require a reason and are always logged with a name.
Two rows in that table need explaining. Money in and money out are manager-only, and they're separate from creating the return. Support can start a return the moment a customer asks, but the refund amount is added by whoever owns the bank account. And the order note writes to Shopify, which means it lands in the customer's own record permanently; the floor packs what the note says rather than changing it. If either split doesn't suit how your team works, tell us and we can change it.
Shared computers
Warehouse stations are shared. So:
- Signing out drops the powerful founder login but lets PIN operators keep working; one button locks the station down between manager visits.
- Team changes (PINs, roles, invites) need a recent founder sign-in — after 15 idle minutes you're asked for the password again. Ordinary settings saves just need the founder signed in; the big one-way actions (data export, workspace deletion, founder accounts) always re-ask.
- The founder never has to type a PIN either: once you've signed in with your email, the workspace knows which team member you are and signs you straight in.
- "Sign out everywhere" ends every browser session if a laptop goes missing.
Built-in protections
- Wrong-PIN and wrong-password attempts get slowed and locked out, and the lockout follows the account, so switching WiFi doesn't reset it.
- Your Shopify/Shiprocket keys are stored encrypted; they're never shown back, never included in exports, and you can rotate them anytime.
- Every brand's data is fenced off from every other brand at the database level, enforced twice over, so a bug in one layer can't cross it.
- Taking someone's access away works straight away, on screens that are already open. Turn a packer off after they leave, change someone's role, or reset a PIN that's been shared around, and the next thing that browser does is refused — you don't have to find the machine and sign it out.
- Changing your founder password signs out every other browser (yours stays signed in). Resetting it by email signs out everything, including whoever asked for the reset, since a reset usually means you think someone else has your password.
- Links we email you — verify your address, reset your password, accept an invite — always point at our own address. That link is a key to your account, so it can never be made to point somewhere else.
The audit trail
Every meaningful action (a confirmation, an address edit, a pack, an override, a dispatch close, a settings change) is written to a permanent activity log with who/what/when. Any order's page shows its own history.
Your data is yours
Settings → Your data gives the founder an export (every order, stock line, movement and record, as CSVs) anytime, and a delete-workspace option that removes everything permanently.
Two things aren't in the export zip: your settings, and the packing photo image files. Ask us and we'll send both.
Deleting the workspace removes your stored files first and the records second. If a file can't be removed, the whole deletion stops and tells you, with nothing else touched, so you can retry it rather than being shown "deleted" while files are still stored.
How long things are kept
Your orders, stock and activity log stay for as long as your workspace exists. They go when you delete it.
Packing photos are deleted automatically after 180 days. A photo of a parcel often catches the shipping label, and that label carries a customer's name and address, so we don't keep them forever. The packing record itself stays — who packed the order and when is still there, and the checklist and barcode history are untouched. Only the picture goes. If your disputes with couriers run longer than that, tell us before you sign up.
The full list of what we keep and for how long is in the privacy policy.
Sounds like your floor? Invite-only pilot. A short email is all it takes.
Request an invite →