Security & your data

Your shop's data, behind sign-in and backed up.

With Shop Cloud: two-step sign-in enforced on the server, integration keys encrypted where browsers can't read them, customer pages that never load your books, change history and nightly backups.

Opens Main Street Auto Service, a made-up sample shop, in your browser. No sign-up.

Two-step sign-in Keys in an encrypted vault Nightly backups
Example · sample shop

Storage

Where your data lives

WPI Driveline Shop Management System keeps the shop's records on each device, in its own browser storage, and works offline.

With Shop Cloud, the shop's data also lives in a private Supabase project for that one shop (Postgres, Realtime, Storage, Edge Functions, Vault). Devices sync live, and offline edits sync later.

Without Shop Cloud

Data lives only in that browser. Clearing browser data erases it, so export backups. Photos and video aren't in the backup file.

How Shop Cloud works
  • Counter PC Works offline
  • Bay iPad Works offline
  • Owner's phone Works offline
Shop CloudA private Supabase project for one shop
  • Postgres
  • Realtime
  • Storage
  • Edge Functions
  • Vault

Logins

Sign-in and two-step

Each person can have their own login. The owner hands out a temporary password (they choose their own at first sign-in), resets passwords and removes access.

Two-step sign-in works with authenticator apps:

  • Google Authenticator
  • Microsoft Authenticator
  • 1Password
  • Authy
  • The phone's built-in password app

For anyone who has it on, or whose role the owner requires it for, it's enforced on the server, so a stolen password alone can't reach data, files or server functions.

The owner can require it for chosen roles and reset it for someone who lost their phone.

Roles

What roles do, plainly

Each person gets one of four roles. Here's what each one opens.

Owner

Everything, including accounting, pay, settings and data.

Shop manager

Runs the shop day to day; no accounting or payroll.

Service advisor

Front counter: repair orders, customers, messages, scheduling and parts.

Technician

Tech clock, workflow, repair orders and technical info.

Shared tablets and bay phones

On a shared counter tablet or bay phone, Who's working? switches people with an optional 4-digit PIN.

Roles and PINs decide which pages each person sees in the app; a PIN is for switching people, not a lock. Every staff login can read the shop's records.

The server itself checks owner-only actions and owner-or-manager actions:

  • Owner onlyMaking or restoring a cloud backup, changing integration keys, connecting Stripe
  • Owner or managerRefunds, QuickBooks
Example · sample shop

Keys

Integration keys stay on the server

Keys for Anthropic, Twilio, Stripe, Resend, Intuit and Smartcar are stored encrypted in Supabase Vault on your Shop Cloud server.

  • Anthropic
  • Twilio
  • Stripe
  • Resend
  • Intuit
  • Smartcar

After saving, a key is never sent back to any device. The screen shows only that it's set, its last four characters and when it changed.

Only your shop's server functions can read keys; the browser can't, even with a staff login.

Example · sample shop

Customers

Customer pages can't see your books

  • Report
  • Live status
  • Booking
  • Check-in
  • Pay
  • Fleet portal
  • None of these pages load shop data. Report, live status and fleet-portal pages read small published files with no costs, margins or internal notes.
  • Report, live status, pay and fleet-portal links use random ids, and share links can be turned off. Booking and check-in read only the shop's public details, such as hours and services.
  • Customers can only add to the inbox (bookings, approvals, messages, check-ins).
  • Photos the browser can open are re-encoded, which removes their GPS location and device data. Files it can't open (such as HEIC outside Safari) and videos are stored as recorded.

Customer pages need Shop Cloud.

Example · sample shop

Payments

Card numbers skip the app; every webhook is checked

Card numbers go to Stripe (Checkout or the reader), never through the app.

Card payments, texts and email run through Shop Cloud on your own Stripe, Twilio and Resend accounts.

Webhooks are the messages Twilio, Stripe and Resend send your Shop Cloud about texts, calls, payments and email. Every webhook is verified: Twilio signatures, Stripe signatures with a 5-minute replay window, and Resend/Svix signatures with a 5-minute window.

Payments & card readers

History & backups

Undo changes from the last six months

With Shop Cloud, every RO, customer and vehicle keeps six months of change history: who changed what, when and from which device. The owner, a manager or an advisor can restore an earlier version in one click.

Cloud backups run every night, the last 14 are kept, and you can download any of them. The owner can restore the whole shop to one, and the current state is backed up first.

Export a backup file any time.

6

months of change history

14

nightly backups kept

Example · sample shop

FAQ

Security questions

All questions
Can we get our data out?

Yes. Export a backup file any time (records only; photos and video aren't in it), plus CSV exports such as the CARFAX service history and payroll.

What if a phone is lost?

The owner removes that login's access and can reset two-step. Once its current session runs out, that phone can't sign in or sync. The copy already stored on the phone isn't erased remotely, so keep shop phones locked with a passcode.

Can staff see the keys?

No. After a key is saved, the screen shows only that it's set, its last four characters and when it changed.

Can customers see my costs?

No. Customer pages read small published files with no costs, margins or internal notes.

Ready when you are

See your own shop day in it.

Send a demo request, or try the sample shop right now.

WPI Driveline Shop Management System

Explore

Features