# Where your shop's data lives, who sees it, and how you get it back

> Data safety in Dashing, plainly: storage on the device during an outage, encryption in transit, every shop isolated in the database, backups, and who sees your data.

By The Dashing team · 2026-09-14

Canonical: https://dashing.krd/en/blog/your-shop-data-safety

"Where does my data go?" is a fair question for anyone leaving the notebook. The notebook has one big flaw (it gets lost or burns) and one big virtue: you know where it is. This article answers the question for Dashing (داشنك) in the shop owner's language rather than the engineer's: where the data is kept at each stage, who sees it, how you get it back, and what we have not done yet.

![Where your shop's data lives and how it is protected at each stage: on the device, in transit, in the database, and in backups](/diagrams/data-safety-en.svg)

## 1. On your device: outage sales are protected until they upload

When the internet drops, sales are saved in the browser's persistent storage on your device, with an explicit request from the system to protect that storage from automatic eviction. When the connection returns they upload in order, once. What you must do: not clear the browser's data while you hold sales that have not uploaded, the screen shows how many are waiting.

## 2. In transit: every connection encrypted

Every connection between your device and the server is encrypted (HTTPS) with a one-year HSTS policy. Nobody on the shop's network or the neighbourhood's can read your invoices on the way.

## 3. In the database: every shop isolated from every other

This is the most important part for a system that serves many shops from one database. Every row is tagged with its shop, and **the database itself**, not only the application, refuses any read or write across the shop boundary. The database account that runs the system has no privilege to bypass that isolation. A bug in the application, if one happened, would hit the database before it reached another shop's data.

## 4. Accounts: passwords we never see, short sessions

Passwords are stored hashed and never as text; sessions are short and renewed with rotating keys that are revoked on sign-out; sign-in attempts from the same address are rate-limited to blunt guessing. Every staff member has their own account and per-screen permissions, and everything they do is in an audit log that cannot be edited or deleted.

## 5. Servers and backups: every night

A **backup is taken every night**; the last 30 daily and 12 monthly copies are kept, with a documented restore procedure. Error monitoring runs without any personal data.

## 6. Your data is yours: export and leaving

Export any list (items, customers, invoices, journal entries) as CSV at any time. If you end your subscription, your data stays available for export for 90 days. No "contact support" to get your own data.

## 7. AI and your privacy

Before any request leaves for the AI model, phone numbers, emails and account-like numbers are masked; Dash reads through tools that respect each user's permissions; every request is recorded in its own log; and every change it proposes waits for your approval. [How Dash answers without inventing a number](/blog/how-dash-answers-without-inventing-numbers) has the details.

## Who can see your data?

- **Your staff**: each according to their per-screen permissions.
- **Your accountant**: through an accountant account you grant and revoke whenever you like.
- **The Dashing team**: administrative access is limited to as few people as possible, for support and maintenance only, through a dedicated account whose use is logged. We do not sell your data or share it with third parties for marketing.
- **The AI model**: the question and the necessary context after masking, not your database.

## What we have not done yet: plainly

- No independent external penetration test yet, and no SOC 2 or ISO 27001 certification.
- A strict browser Content-Security-Policy is deferred to a later release.

To report a vulnerability: message us on WhatsApp from the [contact page](/contact); we treat it seriously and quickly. The [security page](/security) is the complete reference and is updated when any of the above changes.

## Sources

- Security in Dashing, https://dashing.krd/en/security (accessed 2026-09-14)
- Privacy policy, https://dashing.krd/en/legal/privacy (2026-09-14)

## Other languages

- العربية: https://dashing.krd/blog/your-shop-data-safety

---

Dashing · https://dashing.krd/en
