During active work
- Open only the client and order needed for the current task.
- Use the official Order Detail, shipment, return, and exception views instead of copying customer data into personal notes or spreadsheets.
- Keep credentials, private label URLs, full addresses, phone numbers, and email addresses out of chats, tickets, and screenshots.
- Sign out of shared terminals when the work ends and remove temporary paper or local notes according to warehouse policy.
Completed-order boundary
| State | What it means | Safe next step |
|---|---|---|
| Active order | Customer shipping data is visible because it is needed to fulfil or reconcile current work. | Use it only in the official StoreFulfil flow. |
| Completed order | City and country remain for completed-work context, while direct contact and full address data are erased from the completed record. | Use the record as history without recreating a full address. |
| Legacy recovery | An Admin may use the supported recovery path only for the minimum historical context and must not restore full customer data. | Keep the recovered result limited to the supported fields and audit evidence. |
Incident hand-off
- Affected account, order, shipment, or return reference
- Type of data involved, without copying the value
- Time and audience of the exposure
- Immediate containment action
- Admin or privacy owner responsible for the response
What this is and when to use it
Use this when finishing an order or checking what customer shipping information should remain visible.
Close work safely
- Use customer details only in the active order, return, shipment, or exception screen.
- Do not put full addresses, phone numbers, emails, credentials, or private links in notes or tickets.
- After work is complete, sign out of shared terminals and remove temporary paper notes.
- Use the completed record only for the supported history it still displays.
Questions and hand-off
If A completed order no longer shows a full address
Do not recreate it from old paperwork; use the supported history and reference.
If Customer data was shared accidentally
Stop sharing and tell a Warehouse Admin what type of data, when, and with whom, without repeating the value.
What happens next
Completed work keeps only the supported destination context, and any privacy incident has a named owner without copying the exposed value.