Limited public view
Public tracking is designed around shipment status and delivery context, not complete customer or order data.
Shipment Lookup is structured so public visibility and private operational access are different paths.
Public tracking is designed around shipment status and delivery context, not complete customer or order data.
Private records are accessed through signed-in accounts and database policies tied to record ownership.
Privileged credentials belong on trusted infrastructure and should not be embedded in browser code or public links.
A tracking page can show shipment identifiers, status, estimate, event history, carrier labels, and limited route context. It is not intended to expose customer email, phone, full address, payment information, reusable credentials, or internal business notes.
The business console uses Supabase authentication and account-scoped database policies. Signed-in users can work with records owned by their account. A publishable application key identifies the project but does not replace the user's authenticated session or grant privileged access by itself.
Private rows are governed by ownership rules rather than being generally readable from the public client.
Public lookup can use short-lived request counting to make automated enumeration harder.
The public endpoint returns only the fields needed for the customer-facing tracking experience.
Trusted integrations should keep service credentials, private tokens, and reusable secrets on server infrastructure. Public shipment identifiers and publishable project keys should never be treated as substitutes for privileged authentication.
When a connected source is unavailable, the correct behavior is to report a service failure rather than silently translating it into “no shipment found.” That distinction protects both customer trust and operational troubleshooting.
The safest shipment page is not simply one with encrypted transport. It also exposes the minimum useful information, separates estimates from events, avoids credentials in URLs, and gives private business operations a different access path from public tracking.