← Back

Trust & Privacy

This page is maintained by the Mystery Unlock operator to answer common security and privacy questions. It describes current practices and is editable project content — it is not an independent certification or audit.

Access & authentication

  • Shop owners sign in with email and password.
  • Customer spins are gated by single-use access codes issued by the shop owner.
  • Privileged actions (managing shops, reading codes) require an authenticated server-side check.

Data we collect

  • Shop owner: email address and the shop content they create (name, slug, logo, prizes).
  • Customers: an optional first name they type before spinning, and the prize they won.
  • We do not collect payment information through this app.

How data is protected

  • Access codes and spin results are not exposed to the public API; only the server can read or modify them.
  • Public shop pages expose only the shop's display fields (name, slug, logo, prize wheel) — internal owner identifiers are not returned to anonymous visitors.
  • Role grants (e.g. super admin) can only be made server-side; users cannot grant roles to themselves from the client.
  • Row-level security is enabled on all user data tables.

Shared responsibility

Mystery Unlock runs on the Lovable Cloud platform, which provides hosting, managed authentication, and the database. The Mystery Unlock operator is responsible for shop content, prize rules, who they grant admin access to, and how they communicate with their customers.

Data deletion

Shop owners can delete spin records and unused codes from the shop dashboard. To request deletion of an account or all related data, contact the shop operator directly.

Reporting a security issue

If you believe you have found a security issue, please contact the shop operator with details so it can be triaged and addressed.