Access and security
What this page is for: who reaches your accounts, what they can do, and how access ends.
Next step: Email us the role →
Someone you have never met is going to have a login to your store, your email platform and your ad
accounts. That is the real question behind everything else on this site, and it deserves a page
rather than a sentence.
Read this first, because it changes how you should read the rest
This is the policy every seat runs under, published so you can hold us to it from the first day
rather than take our word for it later.
Every line below is a commitment you can test on day one, and you can end the agreement inside
fourteen days if we break one.
THE WHOLE PAGE IN FIVE LINES
- Access lives in your systems. You grant it, you revoke it, one click, no waiting on us.
- We never ask for a password, never see card numbers, and your data never moves to our systems.
- One named operator, working from the Philippines on your hours, employed and paid by us.
- When it ends, you remove access yourself the same day, and nothing leaves with us.
- If we break any line on this page, leave inside fourteen days and pay only for the days used.
The rest of the page is the detail behind each line.
1. Access lives in your systems, never in ours
The single most important section on this page.
You grant it, you own it, you revoke it
Every login is created by you, inside your own Shopify, Klaviyo, Slack, Meta or Google account, as a
named user. We never hold an account you cannot see and cannot switch off. Removing access is one
click in your own admin and needs nothing from us.
Named users only. Never a shared login
One person, one named account, so every action in your audit log carries a name. If anyone ever asks
you to create a generic account or to share an existing one, that request did not come from this
policy and you should refuse it.
Passwords are never sent, and never asked for
Access is granted by invitation inside the platform. We will never ask you to email, message or read
out a password, and you should treat any such request as a warning sign no matter who appears to be
asking.
The least access the work needs
Staff or limited roles rather than owner or admin, unless a specific task genuinely requires more, in
which case we ask for it in writing, for that task, and ask you to remove it afterwards.
Your data stays in your systems
We do not copy your customer lists, order data or subscriber files onto our own systems. Working
documents live in your Drive or your Notion, under your account. When we leave there is nothing to
migrate back, because nothing left.
2. What we will never do
These are not preferences. They are written rules, published before we had a reason to need them.
- Never accept, view or record a full payment card number, from a client or from an operator.
If a task appears to need one, the task changes.
- Never store your customer or subscriber data on Opsbench systems instead of your own.
- Never share, sell or transfer any data we see inside your accounts, to anyone, for any reason.
- Never ask you for a password, or accept one if it is offered.
- Never make a cold call or send a cold text message to a US number. Email only, permanently.
- Never touch protected health information without a signed business associate agreement, named staff and a written handling procedure. Clinical work stays out of scope.
3. Who the operator is, and what is actually checked
Including the parts that are not flattering.
| What you are entitled to know | The answer |
| Where they work from | The Philippines, on your business hours. Your accounts will be accessed from there. We say this before you buy, not during a security review. |
| Who employs them | Opsbench. They are engaged and paid by us. They never become your employee and you take on no payroll obligation. |
| Identity | Verified before engagement, using a government identity document and the sourcing platform's own identity verification where one exists. |
| Screening | A written screen, then a paid work sample on a real page with real problems in it, graded on the reasoning rather than the checklist. We pay for the sample whether or not we move forward. |
| Criminal record check | Not performed today. We will not claim a check we do not run. If your risk profile requires one, say so in your email and we will price it or tell you we are not the right fit. |
| Confidentiality | A written agreement covering confidentiality and intellectual property is signed before any access is granted, and it flows your protections down to the person doing the work. |
4. Devices and accounts
Two factor authentication, everywhere it is offered
On every account, on both sides. Where a platform you use does not offer it, we will name that
platform and tell you what we do instead.
A password manager, never a notebook
Any credential that must exist is held in a password manager, never in a spreadsheet, a chat message
or a document.
Screen lock, disk encryption, current operating system
Required on any device used for your work, and written into the contract rather than hoped for.
5. When it ends
The part most vendors leave vague, which is exactly why it belongs on a public page.
Access ends the same day, and you do not wait for us
Whether an operator is replaced, the agreement ends, or you simply change your mind on a Tuesday, you
remove access yourself in your own admin. Nothing depends on us acting first. We remove our side the
same day and confirm it in writing.
Nothing leaves with us
Everything produced for you is yours. There is no copy on our systems to delete, because there was
never one to make.
A replacement is a new grant, not a handover
If we replace an operator, the new person is invited by you as a new named user and the previous
access is removed. Logins are never passed between people.
6. If something goes wrong
If we believe any of your data or access has been exposed, we tell you the same day we learn of it,
in writing, with what we know, what we do not yet know, and what we have already done. We do not wait
until the picture is complete, because the hours you spend not knowing are the expensive ones.
If you believe something has gone wrong, write to
hello@opsbench.co. One person reads that inbox, and it is the
person who runs this company.
Report a security issue: write to hello@opsbench.co. The same contact and a policy link are published at /.well-known/security.txt.
7. What this page is not
This is not a certification. Opsbench holds no SOC 2 report, no ISO 27001 certificate and no
external security audit, and we will not imply otherwise by decorating this page with badges. If your
procurement process requires any of those, we are not the right fit today, and we would rather you
read that here than find it out on the first day.
What to do next. Opsbench puts one ecommerce operator on your hours, inside your own tools, from $1,650 a month for fifteen hours a week to $2,950 for full time, and nothing is due until their first working day.
Email us the role →
Every line above is a term you can hold us to. The
terms carry the commercial side, and you can leave inside fourteen days paying
only for the days used.
Email us the role →