Talstok
Try it free

How your records are kept safe.

Talstok’s own log-in asks every owner for a second step, each person and each key has a role, and card details stay with Stripe.

Talstok’s own log-in
An emailed code, with a second step for owners, or a passkey alone
Roles
Owner, manager, packer or viewer for each person; manager, packer or viewer for each key
Whole-shop download
The owner only
Customer erasure
The owner, with a dated record of the request
Card details
Held by Stripe, never by Talstok

Logging in

Everyone logs in as themselves, with their own email address.

  • A code by email

    Log in with your email address and a six-digit code sent to it. The code lasts ten minutes, and there is no password to remember.

  • A second step

    After the code, confirm it is you with an authenticator app, which comes with ten recovery codes in case the phone is lost. Or log in with a passkey alone, which counts as both steps. Owners must set up a second step, and so must everyone at a business with a shop that takes real money.

  • Asked again before risky changes

    Changing payments, staff, API keys or the parts switched on, or downloading the whole shop, asks for the second step again unless you gave it in the last ten minutes. A remembered browser skips it at log-in for up to 30 days.

  • Told about new log-ins

    Logging in from a browser you have not used before sends you an email, except the very first time you log in. You can log out of every device at once from your account page. A log-in ends after 7 days unused, and after 30 days at most.

Who can do what

Only an owner can invite, change, suspend or remove someone, and a person’s role covers every shop in the business.

What each person’s role lets them do
RoleWhat they can do
OwnerEverything a manager can do, plus staff and their access, API keys, setting up payments, switching parts on or off, the whole-shop download and erasing a customer.
ManagerProducts, prices, stock, orders, refunds, customers and the import. Cannot change who has access.
PackerPacks and dispatches orders, counts stock and sells at the till. Cannot refund or change prices.
ViewerRead only, for an accountant or an auditor. Cannot use the till.
  • Keys by role

    The owner makes each API key in Settings and gives it one role: manager, packer or viewer. No key can act as the owner, and a revoked key stops working at once.

  • The whole shop, for the owner

    Staff can download the lists their screens show as spreadsheets. Only the owner can download the whole shop, and doing so asks for the second step again.

  • Each shop kept apart

    Each shop’s records are kept in a database of their own, on Cloudflare, and every row is checked against the shop it belongs to. A key names one shop and cannot reach another.

Your customers’ details

  • Erasure, with a dated record

    When a customer asks to be forgotten, the owner can erase their name, email address, phone number and saved addresses, and end their log-ins. It cannot be undone, and a dated record that they asked is kept, even when the request is refused. Orders inside your retention period, which you set at 1 to 30 years, keep their delivery details: once the period has passed, erase the person again to remove them. Orders you have put under a legal hold keep theirs while the hold lasts, and recent payment messages from Stripe may still hold their details until they are cleared, at most 30 days after they arrived. Notes written about them, or about their orders, stay as written, and their customer record at Stripe has to be deleted in Stripe as well.

  • Consent that cannot be rewritten

    When a customer joins or leaves your mailing list, the date and where it happened are kept, along with who recorded it if someone at the business did it for them. That history can never be edited or deleted.

Card payments

  • Card details stay with Stripe

    Online, customers type their card details on Stripe’s own checkout page, so Talstok never sees or holds them. An online order is marked paid only when Stripe sends a signed message for that shop. A sale at the till is marked paid by the signed-in person who takes the money.

  • Card payments into your own Stripe account

    Online card payments go into your own Stripe account at Stripe’s rates. At the counter, cards go through your own card machine.

Questions about security

What if I lose the phone with my authenticator app?

Log in with one of your ten recovery codes, or with a passkey if you have one. Each recovery code works once. If a member of staff loses theirs, the owner can reset their second step.

Only Talstok can reset an owner’s second step, so if you are the owner and have lost the phone and the recovery codes, write to contact@talstok.com.

Does Talstok store card numbers?

No. Online, customers type their card details on Stripe’s own checkout page, and Stripe holds them. At the counter, the card goes through your own card machine, and the till records how the sale was paid and who took it, never the card number.

Can staff download my customer list?

Staff can download the lists their screens show, such as customers and orders, as spreadsheets. Only the owner can download the whole shop.

Who holds my records?

Talstok keeps each shop’s records in a database of their own, on Cloudflare. Card details are held by Stripe.

Can I take all my records with me?

Download your stock, customers and reports as spreadsheets at any time. The owner can also download the whole shop, including the parts that are switched off.

A whole-shop file larger than 40 MB is refused rather than cut short.

See it with your own products

A test shop is free. Nothing in it is real: no money moves, and it never emails a customer. You pay only once a shop takes real money.