Trust
How your store's information is protected — the plain-English version.
Last updated: July 13, 2026
This page is the plain-English version of how ThriftFlow protects the information in your store — written so a store owner, not just an engineer, can tell what's actually done.
Every store runs in its own separate database. One store can't see another's data, and a problem in one never reaches the others. Our own support staff get least-privilege access, per-store passwords, and every time support signs into a store it's recorded in an access log the store can read.
Every store database is backed up nightly, encrypted, and copied off the main server. Restoring a store has been rehearsed end-to-end: a store comes back in about thirteen seconds from a backup. Backups are useless if they don't restore, so we test that they do.
Because stores hold donor and shopper information, ThriftFlow ships the controls a store needs to be a good custodian: export a person's data, erase it on request, and set how long records are kept before they age out automatically.
Only the web and secure-shell ports are open to the internet; the database is never exposed. The system watches its own health — disk, memory, database load, and backup freshness — and raises a flag before a small problem becomes an outage. A weekly automated audit re-checks that every screen, report, and permission still works.
Found something that looks wrong, or have a security question? Email bmanderson22@gmail.com and we'll respond quickly.