Security

How your data is handled

Your boards are stored on Supabase in the United States. Every read from the app is checked against your company. Everything here comes from the privacy policy or the app's code.

Where your data lives and who handles it

Stored in the United States
Your account and board data sit in a Supabase database in the United States. Supabase also runs sign-in. The app and this site run on Railway.
Outside services
The privacy policy names six. Supabase and Railway run ShopBoard. Google Analytics 4 counts visits to this site. MailerLite sends email. Stripe takes payments. Anthropic runs the AI Lean Coach. Your browser also loads the app's fonts from Google Fonts. We don't sell your data or use it for ads.
Plain http gets redirected
A plain http request to the app or this site gets sent to https. The database, Stripe and Anthropic are reached over https too.

Each company only sees its own data

The database does the checking
All 20 tables that hold customer data have Postgres row-level security turned on. Whatever the screen asks for, the database only returns your own company's rows. The one exception is an invite sent to your own email address.
No moving into another company
Nobody can move their login into another company. Another customer's plan and Stripe IDs can't be read.
A test, run by hand
The app's code includes a test that tries things that must be refused, like reading another company's data or raising your own role. It's run by hand, not automated.

Sign-in and who can do what

Email and password
You sign in with an email and a password. The sign-up form asks for at least 8 characters.
Every screen needs a sign-in
That includes the TV on the floor. There are no public board links. The live demo is the one exception. It runs on sample data and never touches the real database.
Three roles
Operator, supervisor and manager. The manager is the account admin. Only a manager can invite people or change roles, and the database enforces it. Nobody can promote themselves.

What the AI Lean Coach sends

Nothing until someone clicks
The coach is on Professional and Enterprise. Nothing goes to Anthropic until someone presses a coach button on a 3C or A3.
What Anthropic receives
The issue title and category. The cell and department. How many times the issue has come back. How many of the cell's last 7 entries in that category were green or red, as counts only. The title, cause and fix of up to 5 resolved issues from that cell and category. The 3C or A3 fields being coached, plus up to 8 earlier messages from the open panel.
What it leaves out
ShopBoard adds no user names, emails or company name. Text your team typed goes as written. If a person's name is in that text, it goes too. A good 3C names a process, not an operator.
The key stays on our server
Your browser never talks to Anthropic. ShopBoard's server checks your plan and settings, then calls Anthropic with a key your browser never sees. What the coach sends isn't used to train models.
ShopBoard doesn't keep the chat
The conversation lives in the open panel and clears when you close it. ShopBoard's server only counts requests per person per day.
The manager sets the rules
In Settings a manager can turn the coach off or block it for operators. They also set daily requests per person, 20 by default. The server refuses a blocked or over-limit request before anything reaches Anthropic. The buttons still show, but pressing one just returns a message.

Payments, copies and deletion

Card details go to Stripe
You type card details on Stripe's own pages. ShopBoard stores no card data, only your Stripe IDs and the state of your plan. The first time an admin starts checkout, we send Stripe their email and the company name.
Only the admin pays
Only a manager can start checkout or open billing, and the server checks. Plan updates from Stripe need a valid Stripe signature.
Getting a copy
There's no spreadsheet export. Email hello@shopboard.live for a copy of your data. In the app, an A3 saves as PDF or PowerPoint and the monthly report as PDF.
Deleting it
There's no delete button in the app. Ask us and we delete your account and data within 30 days. Invoices and other records we must keep for tax or accounting stay. Backups roll off within 30 days after that. Deleting a company removes all of its board data and settings.

What ShopBoard doesn't do

No single sign-on or two-factor
No SAML or Google sign-in, and no MFA. There's no Forgot password link in the app either.
No audit log
SQDC, hour-by-hour and scrap entries record who entered them. Status changes on the Actions page are logged on the action. Neither is a full history of who changed what.
No removing a member in the app
A manager can change someone's role but can't remove them. There's no read-only viewer role either.
No idle timeout
The app has no idle timeout and no list of signed-in devices. Use Sign out on a shared computer.
No certifications
ShopBoard has no SOC 2 or ISO 27001 report to send you.

ShopBoard counts visits with Google Analytics, which sets a cookie to tell one visit from the next. There are no advertising cookies.

In the EU, the UK and Switzerland, analytics cookies are off unless you allow them; everywhere else they’re on unless you turn them off.

Your choice: Not chosen yet (your region’s default)