About Tayrtayr.app/about

How we keep your data safe and what Tayr is built from.

Tayr is the CRM and compliance platform California e-waste collectors and recyclers run their operation on. This page is the straight answer to the two things people ask us directly: how your data is kept safe, and what the platform is built from. It names every service that can touch your records, states what we do and do not have, and points at a source for every infrastructure claim.

React 18TypeScriptViteTailwind CSSCloudflare WorkersHonoDurable ObjectsSQLiteR2 Object StorageCron TriggersGoogle OAuthResendeBay APIs
What it is built from

Six layers, and what each one buys you.

The stack is not exotic, and that is on purpose. Every piece is a managed service with a published SLA, so there is no server in an office to patch and no region that takes the whole CRM down with it.

01Front end

React 18 + TypeScript

Everything you see is a React 18 application written in TypeScript, built with Vite and styled with Tailwind CSS on Radix primitives. The public pages ship as prerendered HTML, so the words are in the page before any JavaScript runs — for crawlers and screen readers alike.

  • React 18, TypeScript, Vite
  • Tailwind CSS, Radix UI primitives
  • Prerendered HTML on public pages
  • One design language, light and dark
02API

Cloudflare Workers + Hono

The API is one Hono application running as a Cloudflare Worker. Cloudflare runs data centers in 330-plus cities across 125-plus countries, so the request that renders your dashboard runs physically close to whoever asked for it. Deploys are atomic and there is no origin server to keep patched.

  • Hono routing, one Worker
  • Runs at the edge, not in one region
  • Zero-downtime atomic deploys
  • Built-in DDoS protection and WAF
03Records

Durable Objects + SQLite

Records live in a Cloudflare Durable Object backed by SQLite. The single-writer model is deliberate: two people logging a load at the same second cannot be handed the same PO number, the same invoice number or the same batch.

  • SQLite-backed Durable Objects
  • Strongly consistent, single writer
  • A separate store per deployment
  • Point-in-time recovery, 30 days
04Files

R2 Object Storage

Pallet photos, signed documents and attachments go to Cloudflare R2, not into the records store. Every download is served by the Worker through the same permission check as the record the file belongs to.

  • R2 for photos, PDFs, scans
  • Permission-checked delivery
  • Retention rules on attachments
  • Encrypted at rest
05Automation

Scheduled Jobs

Three Cloudflare Cron Triggers run outside your browser: an hourly sweep for queued email and marketplace listing health, a nightly pass, and a monthly one that generates billing. Follow-ups and cleanups happen with nobody at a desk and no tab open.

  • Cloudflare Cron Triggers
  • Hourly: queued email, listing health
  • Nightly pass, monthly billing run
  • Runs with no browser open
06Integrations

Google, Resend, eBay

Sign-in is Google OAuth 2.0. Transactional email goes out through Resend — invoices, notifications and invites. Marketplace publishing uses eBay's own APIs and only ever touches the listings you choose to publish. Each one is scoped to the job it does.

  • Google OAuth 2.0 sign-in
  • Resend for transactional email
  • eBay APIs, opt-in per listing
Where your data lives

Separate stores, and every request scoped.

A separate store per deployment. tayr.app and each tenant site — zsrecycling.tayr.app, for example — run as their own Worker with their own Durable Object store, and different deployments cannot read each other's records at all. Inside a deployment, every record carries the account it belongs to and each API request is scoped to the signed-in user's company before anything is returned, so another customer's invoices are absent from the response rather than hidden in the interface.

Nothing sits on a server in an office. Records live in Cloudflare's Durable Object storage, which is attached to the object and, in Cloudflare's own words, "private to its unique instance and cannot be accessed by other objects." Files and photos live in R2 object storage and are served back through the Worker under the same role check as the record they belong to.

Encrypted at rest, encrypted in transit. Cloudflare encrypts all Durable Object data, including metadata, at rest using LUKS disk encryption with AES-256, and R2 objects the same way, with keys managed by Cloudflare. Traffic between your browser and the platform is TLS. Access inside the app is role-based — owner, admin, user — and enforced at the API layer, so a permission you do not hold cannot be reached by calling the endpoint directly, and sensitive actions are logged with the user and the time. More on security.

You are not locked in, and the store is recoverable. SQLite-backed Durable Objects support point-in-time recovery — Cloudflare can restore the store to any point in the past 30 days. Clients, purchase orders, receiving, inventory, invoices and compliance records export to CSV and Excel; invoices, purchase orders, receiving reports, weighmaster certificates and the CalRecycle paperwork print to PDF. On termination the agreement provides a data export, and the data stays yours.

Separate store per deployment · Requests scoped per account · TLS in transit · AES-256 at rest · Role-based access · Audit logging · PITR 30 days · Export any time

Who touches it

Every service that can see your data.

We do not sell or rent your data, and there is no advertising network or third-party tracker inside the product. These are the services we do use, what each one does, and what it can see — each one a named company with published terms you can check yourself. The binding version of this is the Privacy Policy; this is the plain-English version.

Service
What it does for Tayr
What it sees
Cloudflare
Hosting, the records store, file storage, email routing
Platform data, encrypted at rest and in transit
Google
Sign-in with your Google account
Name, email address and profile picture — nothing else
Resend
Transactional email — invoices, notifications, invites
Recipient addresses and the contents of those messages
eBay
Marketplace listing and publishing — off until you turn it on
Only the listing data you publish, plus the seller account you connect

What we hold. The records you create — clients, contacts, purchase orders, receiving, inventory, invoices, weights and the California compliance logs — plus account details (name, email, company) and ordinary usage and log data. What we do not do. We do not sell it, rent it, or feed it to an advertising system, and there is no third-party analytics script following you around the app.

Retention and deletion. Records are kept while your account is active, and you can ask us to delete the account and its data at any time by writing to privacy@tayr.app. That address also handles access, correction and portability requests — see Your Rights in the policy. A closed account passes a 30-day grace window before its records are purged.

FAQ

About Tayr and your data, answered.

What the platform is, where your records live, and what we will and will not claim.

Ask us anything, before you sign.

Request a demo and bring your technical questions — data residency, isolation, exports, retention. We would rather answer them before you sign than after.