Passwords and account security
Reset a password, switch on one-time codes, end a session.
How sign-in works, what an admin can do about it, and the handful of habits that matter more than any setting.
Passwords
Passwords are stored one way only. Nobody can read yours back — not your admin, not our team, not anyone with access to the database. That is why a forgotten password is replaced rather than looked up. There are two ways to replace one.
Yourself: Forgot password
- 1
On the login page, select Forgot password? and enter your email or username.
- 2
Enter the 6-digit code emailed to the address on your account, and choose a new password.
Valid for 15 minutes; five wrong tries locks it. The code only ever goes to the account’s own email.
- 3
Sign in with the new password.
Every device that was signed in is signed out, and a “your password was changed” email is sent — so a reset you didn’t make gets noticed.
For someone else: an admin sets it
For someone who can’t reach their inbox.
- 1
An admin opens the user’s page under Admin → Users.
- 2
On the Password tab, they set a new password and tell the user.
- 3
The user signs in with it straight away.
Setting a new password ends that user’s existing sessions, so anyone signed in as them is signed out.
One-time login codes
Switch one-time codes on for a user and their password stops being enough on its own. After it is accepted, a six-digit code is sent to them and has to be typed in to finish signing in.
- The code works once and expires after ten minutes.
- Codes are stored the same one-way way passwords are — the code itself is never kept.
- The switch is on the user’s Password tab, and an admin controls it.
Tip
Turn codes on for anyone who can reach payments, reports or settings. Those are the logins worth protecting twice.
Sign in with Google
Where a user’s address is a Google account, they can sign in with Google instead of a password. Google has already checked who they are, including whatever two-factor their Google account enforces, so no separate code is sent on that route.
It never creates an account. An address that is not already a user is refused. See Sign in to your account.
Sessions
Signing in creates a session that eventually expires on its own. An admin can see how many devices a user is currently signed in on, and when they last signed in, on the user’s Status tab — and can end every one of those sessions at once.
| Situation | What to do |
|---|---|
| A phone is lost or stolen | Sign out of all sessions for that user. Change the password too if the phone was unlocked. |
| Someone has left the business | Suspend them. That refuses sign-in and ends their sessions. See Add your team. |
| A password may have been shared | Reset it. Existing sessions end with it. |
| Someone is signed in on the shop machine | Sign out on that device. Sessions are per device. |
The habits that matter
- One login per person. Shared logins destroy every trail the app keeps — who recorded a payment, who entered a bill, who adjusted stock.
- Review roles now and then. People get extra access for a task and keep it for years. See Roles and permissions.
- Suspend the day someone leaves, not the week after.
- Keep invoice deletion rare. It is restricted for a reason: a deleted invoice takes its number and its stock movement with it.
Related articles
Last checked against the app on 22 September 2026. Screens change as the product does — if something here does not match what you see, tell us and we will fix the page.