Access control
New users receive no store access until an administrator approves them. Roles are assigned server-side and cannot be self-selected.

DATA HANDLING
Aether Bazaar uses signed-in identity, administrator approval, role checks, and private project storage to protect operational records.
New users receive no store access until an administrator approves them. Roles are assigned server-side and cannot be self-selected.
Products, attendance, sales, and metadata are stored in the site database. Selfies and transaction pictures are stored in private object storage and served only after authorization checks.
The application does not call an AI model, external connector, advertising network, or third-party analytics service with store records.
Administrators can manage approved users. Operators can access operational features only after approval, and protected pictures are checked against their role and assigned locations.
The site runs on OpenAI Sites and uses ChatGPT sign-in. Hosting, identity, retention, and model-training commitments are governed by the owner’s OpenAI plan, workspace settings, and applicable agreement. The application cannot change those account-level settings itself.