Data Security and Backups — Where Your Shop Data Lives
Your billing data is your customer list, your rates and your margins — the most commercially sensitive thing a shop has. This page sets out plainly where it is kept, who can reach it, and what happens if you want it back or want it gone.
Separate, not shared
Every company on MaterialBill has its own isolated data. Your parties, items, rates, bills and ledgers are visible only to logins you have created inside your own account. Another shop using the software cannot see any part of it, including in aggregate. Within your account you control the boundary yourself: a staff login sees only the permissions you tick, so a counter assistant can bill without ever seeing purchase rates, margins or outstanding balances.
Backups, and why cloud is safer than the counter PC
Data is held on managed servers with automatic backups. The usual instinct is that data on your own computer is safer, and in practice it is the opposite: a counter machine is exposed to theft, a failed disk, a power surge and ransomware, and is backed up only when somebody remembers. Losing a phone or a computer here costs you the hardware and nothing else, because you log in on the next device and everything is there.
Access, passwords and what we can see
Logins are individual rather than shared, so actions are attributable — the audit trail records who raised, edited or cancelled a bill. Passwords are stored hashed, never in readable form, which is why we cannot tell you your password and can only reset it. Our support team can access an account to help with a problem when you ask; we do not sell, share or analyse your commercial data, and we do not show advertising inside the product.
Getting your data out, or deleting it
Parties, items, bills and ledgers export to Excel whenever you want, on every plan including the free one. There is no export lock and no notice period. If you want the account and its data deleted, there is a published process at the account deletion page, as required for the Play Store listing, and we act on it. Your data being portable is not a favour — it is the thing that makes the rest of this credible.
What we would tell you to do at your end
Most account compromises in small businesses are not technical. Give every staff member their own login instead of sharing one — a shared password means nobody is accountable and it keeps working after somebody leaves. Remove a login the day a person stops working for you. Do not save the password in a browser on a machine that customers can reach across the counter. And use a different password here from the one on your email, because if the email is compromised everything else follows. None of that costs anything and it prevents the situations we actually see.
What happens if you stop paying
Your data is not held hostage. If a paid plan lapses, the account moves back to free-plan limits rather than being locked or deleted, and your existing records stay readable and exportable. We will not delete a shop's trading history because an invoice went unpaid. Deletion only happens when you ask for it through the published process. This matters more than most security questions, because the commonest way businesses lose their records is not a breach — it is a vendor dispute.
In short
- Each company's data isolated from every other
- Staff logins limited to the permissions you grant
- Managed servers with automatic backups
- Passwords stored hashed, never readable
- Audit trail of who raised, edited or cancelled a bill
- Full export to Excel, and a published deletion process
Frequently asked questions
Can another shop see my data?
Can my staff see my purchase rates?
What if I lose my phone or my computer?
Can I delete my account and data?
More
Start Free Today
Set up in two minutes. No card required. Leave whenever you like — your data always stays yours.