Masking customer data — who can see what
Personal data can be hidden from some roles. There are two mechanisms that are easy to confuse, and addresses are not masked by default at all.
The switch is primary; permissions are granular
These are not two parallel ways of doing the same thing. One is the master switch for all masking; the other controls the details, and it does not work without the first.
| Mechanism | Role | Where |
|---|---|---|
| Privacy masking | Master switch for all masking | Switch in system settings |
| Customer field permissions | Who can see each field when masking is enabled | Field access in roles |
The switch is off by default, which means everyone sees full data. Until you turn it on, removing field access from roles changes nothing: the code checks the switch first and grants full access while it is off. The switch tooltip states this explicitly: “When off, everyone sees full data.”
The most common mistake is removing field permissions and assuming the matter is settled. Nothing works until the switch is enabled (Field permissions — individual fields and individual actions).
Scope of masking
When the switch is enabled, masking applies everywhere customer data leaves the system, not just on warehouse screens:
- customer list and card;
- order list and details, manual order entry, and verification;
- warehouse and returns screens, including returns exports;
- global search—the surname in suggestions is masked too;
- order and customer exports, files that leave the system.
The last two are easiest to overlook in an audit: data can leak not from a screen, but from a spreadsheet someone downloaded.
Step by step
Hide customer fields from a role
- Open Configuration → Team and access → Roles and permissions. You will see the Company roles list.
- Click the pencil icon in the role row (tooltip: Edit role).
- Check Company administrator; it must be off. When it is on, the permissions tabs are hidden and the role can already see everything.
- On Module permissions, leave Read enabled for the Customers module. Removing it masks all customer fields at once, without configuring fields individually.
- Open Field permissions and expand the Client card (the heading has the Customers label). It is near the bottom of the list; scroll down.
- In the Read column, clear the fields that the role should see only in masked form: Client Name, Client Surname, Email Address, Phone Number, NIP / Tax ID. Field names on this card are in English.
- Click Update role.
- Enter the code in the 2FA verification required window and click Confirm. The system will not ask for another code for the next 15 minutes.
Saving sends only fields with Read or Write selected and replaces the entire previous set—clearing a permission really removes access.
Check the effect on a test account
- On the same screen, open User accounts.
- In the test user’s row, open the ⋮ menu and choose Manage roles.
- Select the role you just configured, click Save roles, and confirm with a 2FA code.
- Sign in to that account and open Customers. Fields without read access will be shortened.
Privacy masking switch in system settings
- Open Settings, select System in the section list, then open Session security.
- In Data privacy, switch Customer data masking (GDPR) on or off.
- Click Save.
- Confirm with a code in the 2FA verification required window.
Remember the purpose: this switch does not change the customer database; only field permissions from the procedure above determine what is visible there.
What can be masked on a customer
First name, last name, email, phone, and NIP. A role without read access to a field sees a shortened version:
- first and last name — first and last letters;
- phone — first two and last two digits;
- email — the part before the @ is masked; the domain remains visible.
Masking also applies to exports—the file contains no more than what is visible on screen (Customer export — scope, columns, and the filter trap). Export size makes no difference: a small file prepared immediately and a large file processed in the background and delivered by notification are masked in the same way.
Addresses are not masked by default
In the standard configuration, this module has no permissions for hiding addresses. Every user with access to the module can see customer addresses. Take this into account when assigning roles.
Contact NOXTI support if you need to limit address visibility. Do not assume that permissions for other fields will hide addresses.
One field, two names
In the permissions catalog, the tax ID is called nip; in data and exports, it is vat. They refer to the same thing—look for nip when changing permissions.
The catalog also has a company_name entry that does not correspond to any field and does nothing.
Masked data cannot be saved
An attempt to save a value containing a mask is rejected with an explicit message. This prevents someone from opening a card, saving it unchanged, and overwriting the real phone number with asterisks (Adding and editing a customer — two side effects).
Administrators see everything
The company administrator and superadministrator bypass masking entirely (Company administrator and superadministrator — who bypasses what). When testing the configuration, use an account with the target role, not your own.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo