Data security and privacy

Who can see your company's data, how access rules are enforced, and what leaves the app when you contact support.

NetOrderFlow holds your customer list, your pricing, and your orders. This article explains the boundaries around that data in plain terms, so you know what to expect and what to tell your IT team.

Company isolation

Every record — customers, items, prices, orders, lists, templates, exports — carries the company it belongs to, and access rules are enforced by the database itself rather than by the screens. A request for another company's data returns nothing, regardless of how it is made.

What each role can reach

RoleCan seeCannot do
Sales repCustomers, items, and their own orders (narrowed further if data restriction is on)Change company settings, manage users, or see billing
Customer serviceOrder entry and customer records across the companyChange company settings or manage users
AdminEverything in the company, including settings, users, templates, and billingReach any other company's data

Four further permissions are granted per user on top of the role: export, commit orders, edit prices, manage master data, and view NetSuite IDs. An action you cannot perform is hidden rather than shown and refused.

Roles and permissions in detail

Restricting reps to their own accounts

Admins can turn on data restriction, after which a rep sees only customers and orders tied to their sales rep record or to a territory they are assigned to. Managers additionally see the data of the reps who report to them. The restriction is applied in the database, so it holds for exports and the agent connection too, not just the screens.

Sign-in and sessions

  • Accounts are created by invitation from a company admin — there is no open sign-up that could attach a stranger to your company.
  • Deactivating or locking a user cuts their access immediately; their historical orders stay intact and attributed to them.
  • Admin actions on company data are written to an audit trail.

What support can see

When you send a support request we receive the description you wrote plus the context panel shown in the form: screen, role, plan, browser and device, and the last error message if there was one. We do not receive the contents of the page, your customer or pricing data, or your export files.

If we need to look at a record

Name the order or customer in your request and we will ask before going further. Notes we keep on a request internally are never shown to you and never leave our team.

Exports and files

  • Generated CSV files are stored against the export job and are reachable only by users in your company who hold the export permission.
  • Once a file is downloaded to a laptop it is outside the app — treat it like any other extract of customer data.
  • Agent (MCP) connections act as the user who authorised them and are bound by the same access rules; revoke a connection from settings when it is no longer needed.
Good hygiene

Deactivate leavers the day they leave, keep the export permission to the people who actually load files into NetSuite, and review who holds Admin once a quarter.

Managing users

NetOrderFlow does this for you. Start a 14-day free trial.

Questions about this guide?