Protect the records your shop relies on
Staff access, customer links and payment records have controls to review during setup. The guides explain how to configure the shop and use data tools before exporting or removing records.
Each shop has its own logical database
BenchKey checks shop membership before granting access and selects that shop's logical database. Stores within the same shop share a workspace and can share their customer base.
Shop membership required
- Another shop Own logical database
- Another shop Own logical database
Stores in the same workspace
- Brightfix South End Assigned store access
- Brightfix Downtown
- Brightfix Cambridge
Store access, where configured, limits affected work and records within the shared workspace
Exports check the shop; customer links check the shop, ticket and token
Database ownership checked against the shop, where enabled
Listed infrastructure providers
- Render Application servers and background workers, per provider list
- Neon Managed PostgreSQL; Neon states stored data is encrypted
- Cloudflare R2 Attachments, uploads, exports; Cloudflare states stored objects are encrypted
- TLS in transit A commitment in our data processing agreement
- Integration credentials Designated credentials encrypted before storage by BenchKey
Verify staff access before opening the shop
Staff sign in through Clerk, and BenchKey checks for a verified active session before shop access. Sensitive actions, including a full shop export, require recent authentication.
- Sign-out asks Clerk to end your current session and checks that it ended.
- Revoked sessions and sessions with unfinished required sign-in steps cannot open the shop.
Set access to match each person's work
Owner, Admin, Technician and Viewer roles, custom roles and individual permissions are checked on the server. Only the owner can assign an Admin or custom role.
- Refunds require permission. By default, Admins can refund; Technicians cannot.
- By default, Admins and Technicians cannot delete invoices or edit paid invoice line items.
- Transfer approval requires approval permission and permission to edit inventory at both stores.
- Owners grant or revoke temporary support access; owners and admins review its history.
Review the work recorded by your team
Team Activity brings ticket updates, notes, sent messages and invoice events together by employee, time period and store. Access requires the report in your plan and the permission to view it.
- Team Activity requires permission; default Admins have it, default Technicians don't.
- Admin Activity Log shows template resets, mail-in automation runs and undone completions.
Recorded payments remain open to review
Recorded payments cannot be quietly edited or deleted. Corrections are recorded as new entries, keeping the original payment available for review.
How payment entries workProviders handle card numbers; BenchKey records the payment
Stripe and Square handle card entry in their forms. BenchKey receives tokens or setup references, saving payment records, card brand, last four digits and expiration. Saved cards exclude full numbers and security codes.
Payment providers and hardware-
1Card entry in the provider's form
- Card number and security code
-
2Stripe or Square processes the card
StripeSquareFull card numbers stay with the payment processor
- Token or setup reference
-
3Payment record and saved card details
Saved cards exclude Full card number Security code
Other payment routes
- Stripe Signature checked
- Square Signature checked
- Affirm Signature checked
- Affirm Affirm checkout Checkout reference BenchKey
- Your BenchKey subscription Stripe
Customer links open only the matching job
Status, estimate and invoice links need the matching record and a secret token. They open that customer's job. Internal notes, other customers' tickets, staff accounts and shop exports stay outside that access.
Explore the customer portalChanging the ticket number does not grant access
-
Repair status
- Progress, estimates, invoices and shipments
- Messages and files where included
Shared files have signed download links that expire
-
Estimate approval
- Current estimate terms and amount
- Unexpired estimate
- Typed name and drawn signature
-
Invoice payment
- Server checks before payment
- Rate-limited payments and approvals
Invoice pages request no caching or search indexing
Protected forms verify bot checks on the server
Keep control of your shop's data
Your shop owns its data. Owners can export records. Where available, Delete shop includes a cooling period. Our public data processing agreement commits to regular backups and documented restore procedures.
- Exports exclude secrets, access tokens, IPs, transcripts and recording links.
- Exports remain available until deletion is approved or executing.
Database backup design
- Primary shop database Neon
- Scheduled database backups Cloudflare R2 Separate from the primary database service
- Backup freshness check Alerts for stale or missing backups
Deleting your shop
- 1 Owner confirms deletion request
- 2 Cooling period Download my dataCancel deletion
- 3 Deleted
Kept, and why
- BenchKey billing records
- Proof of terms acceptance
- Security log
- Deletion request record
- Card processors' own records
Where Delete shop is unavailable Request Data Deletion Handled by BenchKey staff
Answers for your security review
Each answer identifies its basis in product behavior, legal terms, provider statements or documented engineering, with a link to the relevant section or document.
Where can we check service availability, uptime history and incidents? Component status, available uptime history, recent incidents and scheduled maintenance
BenchKey's public status page lists each component's current state and available uptime history. It also lists recent incidents and any scheduled maintenance.
System statusWhat evidence can we download for a card chargeback or a legal dispute about a repair? Chargeback responses and complete case records, each with a stored SHA-256 hash
Download Case File offers Chargeback response for card disputes and Complete case record for legal or internal use. Internal technician notes never appear in the Chargeback response; they are optional in the Complete case record. BenchKey stores each downloaded PDF's SHA-256 fingerprint in the case audit log. Review before sharing. Neither document promises a chargeback or legal outcome.
Case filesWhat do the data processing terms cover? Data ownership, processing responsibilities, privacy requests and incident notification
The data processing agreement names your shop as controller and BenchKey as processor. It covers privacy requests, return or deletion, confidentiality, incident notification and international transfers. The subprocessor list names providers. Terms preserve your data ownership and prohibit BenchKey from using customer data to train AI models. The DPA and privacy policy prohibit selling customer personal data.
Data processing agreementWhat engineering checks are documented? Repository tests cover payment integrity, permissions and shop separation
Repository tests cover payment amounts, refunds, chargebacks, shop separation, revoked sessions, permissions and store access. Upload controls restrict file extensions and content types; browser headers limit unsafe content interpretation and framing. A dependency review is documented, and the data processing agreement commits to dependency and code review and remediation.
Security review commitmentsDiscuss your shop's security requirements
Ask about securityThe waitlist is open for repair shops
Leave your email for access updates. Your name and shop name are optional.
Watch the product tour 3:34 Follow a repair from check-in to pickup in BenchKey