Request path
Wix dashboard and signed webhooks → Cirstrata’s HTTPS backend on Railway → Supabase PostgreSQL.
Dashboard requests include a signed Wix app-instance token. Webhooks are signature-verified. The backend binds the verified installation to its stored tenant before data access. Database and Wix credentials stay server-side.
Data used
- Wix installation, site, location, and entitlement references
- Menu item, variant, and modifier references needed for connections
- Ingredients, recipes, settings, connections, and inventory activity
- Operational order references and snapshots used for accounting and recovery
- Feedback and a minimal pseudonymous activation funnel
DishStock does not require buyer names, delivery addresses, or payment-card data for inventory accounting. Merchants are instructed not to put personal data in feedback or stock reasons.
Conservative behavior
Unknown choices do not change stock. Duplicate delivery is idempotent. Physical counts create new per-ingredient baselines. Cancellations require review. Tenant and location scoping is enforced in the application and database.
Retention
Uninstalling stops processing immediately. Installation data enters a 30-day retention period for reinstall recovery, then becomes eligible for deletion by a restricted executor. Provider backups can follow separate cycles.
Contact
Report a security concern to privacy@cirstrata.com. Do not include passwords, access tokens, or customer data.
No SOC 2, ISO, certification, penetration-test, or absolute-security claim is made.