Your data
Where buyer data lives, how you read and export it, and whether you can keep it in your own database.
The Wall is the record of who holds your tools. Your server does not need a copy to check access; when it wants one, it can have one. This page answers the questions a developer asks before trusting a service with customers.
Can I use my own database?
You do not need to. The extension checks entitlement with a signed token and no server of yours. Your server reads the same facts through the API, and hears of changes through webhooks.
You can keep a copy. Sync customers loads a customers table from the API and keeps it current from webhooks. The Wall stays the source of truth: a licence, subscription or grant exists because the Wall says so, and the extension asks the Wall, not your table.
What you store beside the copy is yours: preferences, usage, your own product's data. Key it by the buyer's email, which the Wall uses as the buyer's identity, or by user_id from the webhooks.
What the Wall stores
| About | Stored | Not stored |
|---|---|---|
| A buyer | Email, name if they gave one, language, sign-in method, the Google account if connected | A password (sign-in is by link or Google) |
| A licence | A SHA-256 hash of the key and its prefix, the plan, dates, status, the Stripe payment id, the buyer's email | The key itself |
| A device | A device id, the public half of its key pair, the browser, first and last seen, the extension version it last reported, and the addresses it was seen from until it has been quiet for 90 days | Anything about the pages the person visits |
| A subscription | Stripe's subscription id, status, period, plan | Card details, which stay with Stripe |
| Free-plan use | A per-device count | |
| A trial | A keyed hash of the inbox it was started from, so each inbox has one trial of a tool | The address |
| Check-ins | A count a tool, a day and a build: how often copies asked for the tool's policy | Anything about the device or the person |
| Support | Notes you write, refunds, grants, blocks |
Payment details never reach the Wall. Stripe holds them on your account.
Where it is
| Provider | Location | |
|---|---|---|
| Database | Supabase | Frankfurt |
| Application | Vercel | Frankfurt |
| Rate limits and replay protection | Upstash | Frankfurt |
| Amazon SES | Stockholm | |
| Webhook delivery | Svix | EU |
| Payments | Stripe | Your Stripe account, under Stripe's terms |
These are the sub-processors, as listed in the privacy policy. A change to the list is announced to workspace owners by email before it takes effect.
Access
- Buyers live in a pool per workspace. Another workspace cannot read them.
- Members of your workspace see customers according to their role.
- Every table is protected by row-level security; card numbers never reach the Wall.
Retention
| Data | Kept |
|---|---|
| Accounts, licences, subscriptions, devices | While the account or the purchase exists, then as long as your legal obligations require: a purchase record outlives the licence |
| Security and abuse records | No longer than twelve months |
| Sign-in links, one-time tokens, device codes | Minutes; deleted when used or expired |
| Check-ins (Versions → In use) | 35 days |
| Webhook deliveries | On the endpoint under Configure → Webhooks, for Svix's retention period |
| Support notes | With the customer |
A deletion request is carried out within thirty days, keeping only what the law requires.
The person's rights
From a customer's page you can Download everything the Wall holds about a person as JSON, and Erase them: the account, devices, sign-ins and notes are deleted; licences and payments are kept as records of the sale, with the email replaced by a hash of it. A buyer can delete their own account from their account page; see Buyer pages.
Taking it with you
Configure → Export downloads the whole workspace, signing keys included. See Export.
Agreements
The Wall processes buyer data on your behalf under the terms and the privacy policy, which buyers reach from the foot of every page. A data processing agreement for your own records is available on request at hello@toolaby.app.