Toolaby Wall

Your data

Where buyer data lives, how you read and export it, and whether you can keep it in your own database.

The Wall is the record of who holds your tools. Your server does not need a copy to check access; when it wants one, it can have one. This page answers the questions a developer asks before trusting a service with customers.

Can I use my own database?

You do not need to. The extension checks entitlement with a signed token and no server of yours. Your server reads the same facts through the API, and hears of changes through webhooks.

You can keep a copy. Sync customers loads a customers table from the API and keeps it current from webhooks. The Wall stays the source of truth: a licence, subscription or grant exists because the Wall says so, and the extension asks the Wall, not your table.

What you store beside the copy is yours: preferences, usage, your own product's data. Key it by the buyer's email, which the Wall uses as the buyer's identity, or by user_id from the webhooks.

What the Wall stores

AboutStoredNot stored
A buyerEmail, name if they gave one, language, sign-in method, the Google account if connectedA password (sign-in is by link or Google)
A licenceA SHA-256 hash of the key and its prefix, the plan, dates, status, the Stripe payment id, the buyer's emailThe key itself
A deviceA device id, the public half of its key pair, the browser, first and last seen, the extension version it last reported, and the addresses it was seen from until it has been quiet for 90 daysAnything about the pages the person visits
A subscriptionStripe's subscription id, status, period, planCard details, which stay with Stripe
Free-plan useA per-device count
A trialA keyed hash of the inbox it was started from, so each inbox has one trial of a toolThe address
Check-insA count a tool, a day and a build: how often copies asked for the tool's policyAnything about the device or the person
SupportNotes you write, refunds, grants, blocks

Payment details never reach the Wall. Stripe holds them on your account.

Where it is

ProviderLocation
DatabaseSupabaseFrankfurt
ApplicationVercelFrankfurt
Rate limits and replay protectionUpstashFrankfurt
EmailAmazon SESStockholm
Webhook deliverySvixEU
PaymentsStripeYour Stripe account, under Stripe's terms

These are the sub-processors, as listed in the privacy policy. A change to the list is announced to workspace owners by email before it takes effect.

Access

  • Buyers live in a pool per workspace. Another workspace cannot read them.
  • Members of your workspace see customers according to their role.
  • Every table is protected by row-level security; card numbers never reach the Wall.

Retention

DataKept
Accounts, licences, subscriptions, devicesWhile the account or the purchase exists, then as long as your legal obligations require: a purchase record outlives the licence
Security and abuse recordsNo longer than twelve months
Sign-in links, one-time tokens, device codesMinutes; deleted when used or expired
Check-ins (Versions → In use)35 days
Webhook deliveriesOn the endpoint under Configure → Webhooks, for Svix's retention period
Support notesWith the customer

A deletion request is carried out within thirty days, keeping only what the law requires.

The person's rights

From a customer's page you can Download everything the Wall holds about a person as JSON, and Erase them: the account, devices, sign-ins and notes are deleted; licences and payments are kept as records of the sale, with the email replaced by a hash of it. A buyer can delete their own account from their account page; see Buyer pages.

Taking it with you

Configure → Export downloads the whole workspace, signing keys included. See Export.

Agreements

The Wall processes buyer data on your behalf under the terms and the privacy policy, which buyers reach from the foot of every page. A data processing agreement for your own records is available on request at hello@toolaby.app.

On this page