What we do — and don't do — with your store's data.
Jewelers handle high-value merchandise and long customer histories. You should not need to guess what happens under the hood. This page is meant to answer everything without you having to email us — but if we've missed your question, we're one message away.
- Legal entity
- Fourfold LLC (Sacramento, CA)
- Hosting
- Firebase / Google Cloud (US)
- Auth
- Firebase Authentication + 2FA
- Data in transit
- TLS 1.2+ (HSTS enforced)
- Data at rest
- AES-256 (managed by Google Cloud)
- Backups
- Automated daily · retained 30 days
Who can sign in — and how we know it's them
Two-factor authentication on every account
TOTP-based 2FA is available for every staff account and required for store owners by default. No SMS-based fallback (SMS is the attack surface, not the defense).
Role-based access
Owner, manager, and counter-staff roles ship out of the box. Roles are per store — a manager at Location A does not see Location B's data unless explicitly granted.
Session management
Sessions expire after inactivity. Owners can revoke any staff session from the admin dashboard.
Yours, always — with no lock-in
One-click CSV export
Your full catalog, customer records, sales history, repair queue, and layaway ledger export to CSV any time. No ticket, no wait.
AI does not train on your data
Prompts sent to the AI Design Generator and inputs to the Growth Agents stay in your store. We do not use them to train models and we do not share them across stores.
Data location
All customer data is stored in Firebase / Google Cloud US-region datacenters. If you need EU or India residency, tell us and we'll walk through options.
The plumbing
Encrypted in transit
TLS 1.2+ on every connection. HSTS enforced. HTTP requests get 301'd to HTTPS at the edge.
Encrypted at rest
AES-256, managed by Google Cloud key management. Backups are encrypted the same way.
Payments never touch our servers
Card processing is handled by Stripe. Card numbers, CVVs, and expiry dates go directly from your customer's device to Stripe — we only see the last four digits and a token.
How we run the service
Least-privilege access
Engineers do not have production customer-data access as part of their default role. Access requires an explicit request with a documented reason.
Automated daily backups
Retained for 30 days. Point-in-time restore available for the last 24 hours.
Vulnerability disclosure
Found something? Email security@fourfoldllc.com. We respond within one business day and credit responsible reporters if desired.
What we're honest about NOT having yet
SOC 2 Type II
We're not certified today. If your procurement team needs it and you're a serious multi-store lead, tell us and we'll share our current runbook + timeline.
EU / India data residency
US-only today. Available on request for multi-store deployments.
SSO / SAML
Not shipped yet. On the roadmap for chain accounts. Firebase supports it under the hood.
Missing something you'd need for procurement?
If your IT / security team has a checklist, send it. We'll answer every row — or tell you honestly if we're not there yet and where we are on our roadmap.