Security
How your data is handled
Your boards are stored on Supabase in the United States. Every read from the app is checked against your company. Everything here comes from the privacy policy or the app's code.
Where your data lives and who handles it
- Stored in the United States
- Your account and board data sit in a Supabase database in the United States. Supabase also runs sign-in. The app and this site run on Railway.
- Outside services
- The privacy policy names six. Supabase and Railway run ShopBoard. Google Analytics 4 counts visits to this site. MailerLite sends email. Stripe takes payments. Anthropic runs the AI Lean Coach. Your browser also loads the app's fonts from Google Fonts. We don't sell your data or use it for ads.
- Plain http gets redirected
- A plain http request to the app or this site gets sent to https. The database, Stripe and Anthropic are reached over https too.
Each company only sees its own data
- The database does the checking
- All 20 tables that hold customer data have Postgres row-level security turned on. Whatever the screen asks for, the database only returns your own company's rows. The one exception is an invite sent to your own email address.
- No moving into another company
- Nobody can move their login into another company. Another customer's plan and Stripe IDs can't be read.
- A test, run by hand
- The app's code includes a test that tries things that must be refused, like reading another company's data or raising your own role. It's run by hand, not automated.
Sign-in and who can do what
- Email and password
- You sign in with an email and a password. The sign-up form asks for at least 8 characters.
- Every screen needs a sign-in
- That includes the TV on the floor. There are no public board links. The live demo is the one exception. It runs on sample data and never touches the real database.
- Three roles
- Operator, supervisor and manager. The manager is the account admin. Only a manager can invite people or change roles, and the database enforces it. Nobody can promote themselves.
What the AI Lean Coach sends
- Nothing until someone clicks
- The coach is on Professional and Enterprise. Nothing goes to Anthropic until someone presses a coach button on a 3C or A3.
- What Anthropic receives
- The issue title and category. The cell and department. How many times the issue has come back. How many of the cell's last 7 entries in that category were green or red, as counts only. The title, cause and fix of up to 5 resolved issues from that cell and category. The 3C or A3 fields being coached, plus up to 8 earlier messages from the open panel.
- What it leaves out
- ShopBoard adds no user names, emails or company name. Text your team typed goes as written. If a person's name is in that text, it goes too. A good 3C names a process, not an operator.
- The key stays on our server
- Your browser never talks to Anthropic. ShopBoard's server checks your plan and settings, then calls Anthropic with a key your browser never sees. What the coach sends isn't used to train models.
- ShopBoard doesn't keep the chat
- The conversation lives in the open panel and clears when you close it. ShopBoard's server only counts requests per person per day.
- The manager sets the rules
- In Settings a manager can turn the coach off or block it for operators. They also set daily requests per person, 20 by default. The server refuses a blocked or over-limit request before anything reaches Anthropic. The buttons still show, but pressing one just returns a message.
Payments, copies and deletion
- Card details go to Stripe
- You type card details on Stripe's own pages. ShopBoard stores no card data, only your Stripe IDs and the state of your plan. The first time an admin starts checkout, we send Stripe their email and the company name.
- Only the admin pays
- Only a manager can start checkout or open billing, and the server checks. Plan updates from Stripe need a valid Stripe signature.
- Getting a copy
- There's no spreadsheet export. Email hello@shopboard.live for a copy of your data. In the app, an A3 saves as PDF or PowerPoint and the monthly report as PDF.
- Deleting it
- There's no delete button in the app. Ask us and we delete your account and data within 30 days. Invoices and other records we must keep for tax or accounting stay. Backups roll off within 30 days after that. Deleting a company removes all of its board data and settings.
What ShopBoard doesn't do
- No single sign-on or two-factor
- No SAML or Google sign-in, and no MFA. There's no Forgot password link in the app either.
- No audit log
- SQDC, hour-by-hour and scrap entries record who entered them. Status changes on the Actions page are logged on the action. Neither is a full history of who changed what.
- No removing a member in the app
- A manager can change someone's role but can't remove them. There's no read-only viewer role either.
- No idle timeout
- The app has no idle timeout and no list of signed-in devices. Use Sign out on a shared computer.
- No certifications
- ShopBoard has no SOC 2 or ISO 27001 report to send you.