Skip to content

Security and data in Support: storage, access, links, deletion

Requests, messages, customers and settings are stored in a Cloudflare D1 database; attached images are stored in Cloudflare R2. Emails go out through the fewbase platform, which sends them via Resend — the same processor as for every fewbase tool. The platform-wide description of processors and retention is in the Privacy Policy; this page covers what Support adds on top.

For each request, Support keeps the customer’s email and the name they typed, the subject and messages, the images, the source (portal, widget or app), the page of your site the widget was opened from, and the browser’s user-agent string at the time of sending.

  • You — every request, message, image and customer of your service, after signing in to fewbase. Nobody else’s service is visible, and a link or image from one service never opens data from another.
  • The customer — only their own requests, by their personal link. The thread shows your replies signed with the service name; agents’ names and emails are not shown.
  • Images are served only through Support, with the customer’s link or your session; there are no public URLs to the storage.

The portal and customer pages are marked noindex for search engines.

  • The confirmation link in the first email is a one-time token that lasts 24 hours. Only a hash of it is stored; opening the link does not create the request — pressing the button on the page does, so a mail scanner that follows links cannot confirm on the customer’s behalf.
  • The personal link (“Your requests”) is a long random token, one per customer per service. It lives until revoked — press Revoke link on the customer card, and the old link stops working at once while the customer gets a new one by email. See Customers.
  • Emails to customers are sent from the platform address with your service name; they carry the personal link and never a password.

With Confirm the sender’s email off in Settings, anyone can type someone else’s address in the form and create a request in that person’s name. See What your customer sees. Several things limit the damage:

  • The sender never sees the thread or the personal link. Both go only to the address typed in the form, by email. Someone typing another person’s address gets nothing back: they cannot read the reply or the rest of that person’s requests.
  • The email to that address carries no words from the sender. The “Request #N received” email shows only the request number, your service name and the personal link, so the form cannot be used to send someone arbitrary text from your service.
  • Unverified requests don’t use up your monthly limit. They count only once the customer confirms the address through their link, so requests typed with other people’s addresses can’t stop your intake for the month.
  • Turnstile still runs on every request, guest or not.
  • A cap per address: no more than 3 unverified requests from one address to one service, and 5 across all services, within 24 hours. See Plans and limits.
  • The “email not verified” label in the inbox and thread (see Requests) flags the request until the customer acts on their personal link, so you know not to trust it fully before that.
  • Deletion. An unverified request can be removed. See Requests.

Settings → Delete service removes the service and everything in it — requests, messages, customers and images — from the live database and storage at once; as for every fewbase tool, backups are cleared as they rotate. There is no undo, and the deletion is your action alone: fewbase does not delete or edit requests, messages or customers inside a service.

Your customers deal with you, not with fewbase, and you are the one who decides what happens to their requests. What you can do today:

  • Show them their data. Their personal link already lists every request and message they sent to you.
  • Stop email. Closing a request sends one email; after that, no further email goes out unless you reply again.
  • Delete their data. There is no per-customer delete in the interface yet — a single customer and their requests are removed only with the whole service. If a customer asks you to erase their data and deleting the service is not an option, write to info@opentech.ee with the service address and the customer’s email — fewbase removes it by hand, the same way account deletion is handled for the platform.
Does Support read the messages?

No. Messages are plain text stored as typed; nothing analyses or filters them. The only automation is auto-close, which changes a status and sends one email.