Protect the records your shop relies on

Staff access, customer links and payment records have controls to review during setup. The guides explain how to configure the shop and use data tools before exporting or removing records.

Each shop has its own logical database

BenchKey checks shop membership before granting access and selects that shop's logical database. Stores within the same shop share a workspace and can share their customer base.

Signed in Maria Lopez Tech
Shop membership check Before shop access is granted

Shop membership required

  • Another shop Own logical database
  • Another shop Own logical database
Brightfix Repair Own logical database

Stores in the same workspace

  • Brightfix South End Assigned store access
  • Brightfix Downtown
  • Brightfix Cambridge
Shared customer base

Store access, where configured, limits affected work and records within the shared workspace

Export Data Brightfix Repair
Customer status link #23115

Exports check the shop; customer links check the shop, ticket and token

Database ownership checked against the shop, where enabled

Listed infrastructure providers

  • Render Application servers and background workers, per provider list
  • Neon Managed PostgreSQL; Neon states stored data is encrypted
  • Cloudflare R2 Attachments, uploads, exports; Cloudflare states stored objects are encrypted
  • TLS in transit A commitment in our data processing agreement
  • Integration credentials Designated credentials encrypted before storage by BenchKey

Verify staff access before opening the shop

Staff sign in through Clerk, and BenchKey checks for a verified active session before shop access. Sensitive actions, including a full shop export, require recent authentication.

  • Sign-out asks Clerk to end your current session and checks that it ended.
  • Revoked sessions and sessions with unfinished required sign-in steps cannot open the shop.
Read the sign-in guide
1Clerk handles staff sign-in; BenchKey checks for a verified active session.
2Manage two-step sign-in in your account; BenchKey shows whether it is on.

Set access to match each person's work

Owner, Admin, Technician and Viewer roles, custom roles and individual permissions are checked on the server. Only the owner can assign an Admin or custom role.

  • Refunds require permission. By default, Admins can refund; Technicians cannot.
  • By default, Admins and Technicians cannot delete invoices or edit paid invoice line items.
  • Transfer approval requires approval permission and permission to edit inventory at both stores.
  • Owners grant or revoke temporary support access; owners and admins review its history.
Read about team roles
Assigned stores and roles
Actions reserved for the owner
Viewer access keeps business records read-only

Review the work recorded by your team

Team Activity brings ticket updates, notes, sent messages and invoice events together by employee, time period and store. Access requires the report in your plan and the permission to view it.

  • Team Activity requires permission; default Admins have it, default Technicians don't.
  • Admin Activity Log shows template resets, mail-in automation runs and undone completions.
Explore the reports

Recorded payments remain open to review

Recorded payments cannot be quietly edited or deleted. Corrections are recorded as new entries, keeping the original payment available for review.

How payment entries work

Providers handle card numbers; BenchKey records the payment

Stripe and Square handle card entry in their forms. BenchKey receives tokens or setup references, saving payment records, card brand, last four digits and expiration. Saved cards exclude full numbers and security codes.

Payment providers and hardware
  1. 1Card entry in the provider's form

  2. Card number and security code
  3. 2Stripe or Square processes the card

    StripeSquare

    Full card numbers stay with the payment processor

  4. Token or setup reference
  5. 3Payment record and saved card details

    Saved cards exclude Full card number Security code
Other payment routes
  • Stripe Signature checked
  • Square Signature checked
  • Affirm Signature checked
BenchKey payment record
  • Affirm Affirm checkout Checkout reference BenchKey
  • Your BenchKey subscription Stripe

Keep control of your shop's data

Your shop owns its data. Owners can export records. Where available, Delete shop includes a cooling period. Our public data processing agreement commits to regular backups and documented restore procedures.

  • Exports exclude secrets, access tokens, IPs, transcripts and recording links.
  • Exports remain available until deletion is approved or executing.
Read the privacy tools guide

Database backup design

  1. Primary shop database Neon
  2. Scheduled database backups Cloudflare R2 Separate from the primary database service
  3. Backup freshness check StaleMissing Alerts for stale or missing backups

Deleting your shop

  1. 1 Owner confirms deletion request
  2. 2 Cooling period Download my dataCancel deletion
  3. 3 Deleted

Kept, and why

  • BenchKey billing records
  • Proof of terms acceptance
  • Security log
  • Deletion request record
  • Card processors' own records

Where Delete shop is unavailable Request Data Deletion Handled by BenchKey staff

Some records remain for legal or security reasons; backup copies expire separately.

Answers for your security review

Each answer identifies its basis in product behavior, legal terms, provider statements or documented engineering, with a link to the relevant section or document.

Where can we check service availability, uptime history and incidents? Component status, available uptime history, recent incidents and scheduled maintenance Product behavior

BenchKey's public status page lists each component's current state and available uptime history. It also lists recent incidents and any scheduled maintenance.

System status
System status
What evidence can we download for a card chargeback or a legal dispute about a repair? Chargeback responses and complete case records, each with a stored SHA-256 hash Product behavior

Download Case File offers Chargeback response for card disputes and Complete case record for legal or internal use. Internal technician notes never appear in the Chargeback response; they are optional in the Complete case record. BenchKey stores each downloaded PDF's SHA-256 fingerprint in the case audit log. Review before sharing. Neither document promises a chargeback or legal outcome.

Case files
Case files
What do the data processing terms cover? Data ownership, processing responsibilities, privacy requests and incident notification Legal commitment

The data processing agreement names your shop as controller and BenchKey as processor. It covers privacy requests, return or deletion, confidentiality, incident notification and international transfers. The subprocessor list names providers. Terms preserve your data ownership and prohibit BenchKey from using customer data to train AI models. The DPA and privacy policy prohibit selling customer personal data.

Data processing agreement
Data processing agreement
What engineering checks are documented? Repository tests cover payment integrity, permissions and shop separation Repository evidence

Repository tests cover payment amounts, refunds, chargebacks, shop separation, revoked sessions, permissions and store access. Upload controls restrict file extensions and content types; browser headers limit unsafe content interpretation and framing. A dependency review is documented, and the data processing agreement commits to dependency and code review and remediation.

Security review commitments
Security review commitments

Discuss your shop's security requirements

Ask about security

The waitlist is open for repair shops

Leave your email for access updates. Your name and shop name are optional.

Watch the product tour 3:34 Follow a repair from check-in to pickup in BenchKey