Security & data practices
Last updated September 24, 2026
Spine separates store inventory by membership and role. This page describes current controls without promising a certification or a particular uptime level.
Account and store access
Sign-in runs through an identity provider. The application checks active store membership and permissions for store-scoped requests. Store owners and managers control staff invitations and roles. Email verification is required before store access. Auth and inventory actions also create records used for accountability.
Sessions and media
The application uses an essential protected sign-in cookie and tab-scoped session state. Optional profile photos are stored privately and accessed through short-lived signed links. Replaced or removed photos enter a cleanup process.
Operations and recovery
Primary application services and databases run on operator-managed infrastructure in Raleigh, North Carolina. Cloudflare helps serve the public domains; Google Cloud supports messaging, profile-media storage and offsite backups; AWS SES delivers transactional email. Spine monitors service health and keeps database backups for recovery. Backup retention follows a rolling backup configuration, not a guaranteed number of days.
Limits and contact
No online service can guarantee that every failure or attack will be prevented. We do not claim SOC 2 certification or a formal uptime guarantee. To report a suspected security problem, email [email protected] with a brief description and a safe way to reach you. Please do not send passwords or other secrets by email. We will investigate and coordinate with affected providers and users as appropriate.
Read the Privacy Policy for the categories of data Spine handles, or request access, export, or deletion review.