Support access to your store admin
This document sets out on what grounds, for how long, and with what record a support engineer may enter your store's admin.
1.General rule
- Support holds no standing access to your store. There is no role that sees every store.
- Each entry is a separate event: a stated reason, a limited duration, a log record.
2.Grounds for entry
- A support request opened by you. The request itself is the documented instruction.
- A separate request from support, where the problem was found on our side. Your approval is the instruction here; it is not given in advance or open-endedly.
- Emergency entry, in the cases set out in section 6.
3.What approval covers
- The reason: the text the engineer wrote. You see it verbatim, not a category from a list.
- The duration: 30, 60, 120 minutes to choose from. A specific value is approved.
- The scope: one store. The grant does not extend to any other store.
4.Time limits
- A request awaits an answer for up to 72 hours, after which it lapses.
- An unused approval remains valid for 8 hours.
- A session runs for the approved number of minutes (30, 60, 120) and is counted from the actual entry. Entering again does not extend it.
5.Revocation
- Access is ended under "Security" in the admin.
- Revocation takes effect immediately, regardless of the work in progress.
6.Emergency entry
- Used only where waiting for approval would deepen the harm: an outage, or abuse in progress.
- You are notified by email at the moment of entry.
- Duration: 30 minutes, with no choice of value.
- A written justification is filed within 24 hours and reviewed by someone other than the person who entered.
- Requires a separate permission that an ordinary support account does not hold. Marked separately in the log.
7.Access log
- Recorded: the request and its reason, approval or refusal, the start and end of the session, each individual entry, and every grant or removal of a staff permission.
- Changing and deleting records is blocked by triggers inside the database, not by application code.
- Each record carries a cryptographic digest of the one before it, computed by the database. Inserting, altering or removing a row breaks the chain and shows up on verification.
- A staff member's IP address is stored as a hash; the address itself is not in the log.
- Records for your own store are available in the admin without a separate request. Retention: 24 months.
8.Scope of this document
- This document concerns entry into the store admin.
- It does not cover infrastructure-level access to the database and backups, required to run the service, update it and restore from backup; that access does not pass through approval.
- Infrastructure access is held by one person bound by confidentiality, exercised only from within the EU.
- It does not cover disclosure required by law, including a lawful demand from a public authority. Such a demand is reviewed, complied with only to the extent actually compelled, and where possible the requester is directed to you. Notice is given unless the law forbids it.
- Accordingly, a claim that all access to your data passes through your approval would be inaccurate.
This page describes the current arrangement and is not a contract. The commitments on access are set out in Annex B:
Data Processing Agreement