Data security and privacy
Who can see your company's data, how access rules are enforced, and what leaves the app when you contact support.
NetOrderFlow holds your customer list, your pricing, and your orders. This article explains the boundaries around that data in plain terms, so you know what to expect and what to tell your IT team.
Company isolation
Every record — customers, items, prices, orders, lists, templates, exports — carries the company it belongs to, and access rules are enforced by the database itself rather than by the screens. A request for another company's data returns nothing, regardless of how it is made.
What each role can reach
| Role | Can see | Cannot do |
|---|---|---|
| Sales rep | Customers, items, and their own orders (narrowed further if data restriction is on) | Change company settings, manage users, or see billing |
| Customer service | Order entry and customer records across the company | Change company settings or manage users |
| Admin | Everything in the company, including settings, users, templates, and billing | Reach any other company's data |
Four further permissions are granted per user on top of the role: export, commit orders, edit prices, manage master data, and view NetSuite IDs. An action you cannot perform is hidden rather than shown and refused.
Roles and permissions in detail
Restricting reps to their own accounts
Admins can turn on data restriction, after which a rep sees only customers and orders tied to their sales rep record or to a territory they are assigned to. Managers additionally see the data of the reps who report to them. The restriction is applied in the database, so it holds for exports and the agent connection too, not just the screens.
Sign-in and sessions
- Accounts are created by invitation from a company admin — there is no open sign-up that could attach a stranger to your company.
- Deactivating or locking a user cuts their access immediately; their historical orders stay intact and attributed to them.
- Admin actions on company data are written to an audit trail.
What support can see
When you send a support request we receive the description you wrote plus the context panel shown in the form: screen, role, plan, browser and device, and the last error message if there was one. We do not receive the contents of the page, your customer or pricing data, or your export files.
Name the order or customer in your request and we will ask before going further. Notes we keep on a request internally are never shown to you and never leave our team.
Exports and files
- Generated CSV files are stored against the export job and are reachable only by users in your company who hold the export permission.
- Once a file is downloaded to a laptop it is outside the app — treat it like any other extract of customer data.
- Agent (MCP) connections act as the user who authorised them and are bound by the same access rules; revoke a connection from settings when it is no longer needed.
Deactivate leavers the day they leave, keep the export permission to the people who actually load files into NetSuite, and review who holds Admin once a quarter.
Managing users
NetOrderFlow does this for you. Start a 14-day free trial.
Questions about this guide?