Account and sign-in
An account is the business owner and everything that belongs to them: locations, catalogue, orders, staff, subscription. There is one account per business, no matter how many locations it holds (see Multi-location), and people get in differently: the owner with their e-mail, staff with their own logins or a PIN at the till, tablets and screens with a device code.
What you need to get started#
- A working e-mail and access to that mailbox. The confirmation code, password recovery letters and the account handover letter all go there.
- A browser. Sign-up and sign-in live at
admin.cenaly.com/registerandadmin.cenaly.com/login. - A password of at least 8 characters. On reset and change its strength is checked: an upper-case and a lower-case letter, a digit, a special character.
- Nothing else: no phone number, no card and no app are needed to register.
Registration#
| Method | Where | Where it works |
|---|---|---|
| E-mail and password | /register |
On every brand |
| Button above the form | cenaly.com, cenaly.com | |
| Button above the form | cenaly.com, cenaly.com | |
| VK ID, Mail, Odnoklassniki, Yandex ID, Sber ID, Gosuslugi | Buttons above the form | Only on cenaly.ru |
| A printed QR code (flyer, sticker) | /register?code=… or the camera scanner |
cenaly.com, cenaly.com |
E-mail and password. The password is at least 8 characters with a confirmation field, plus a mandatory checkbox accepting the Terms and the Privacy Policy. On cenaly.com and cenaly.com the address is confirmed by a code from an e-mail (6 digits, the form is right on the page), after which you are signed in automatically. On cenaly.ru there is no code confirmation — the account opens immediately.
Social buttons are both sign-up and sign-in. An unknown address creates an account, a known one simply signs in; there is no separate "register with Google".
From a printed QR code you "claim" a code from a flyer or a sticker: you can protect it with a PIN (4 digits) or a password, or deliberately leave it unprotected — there is a separate checkbox that accepts the risk. After a successful claim the system signs you in with that same code.
Acceptance of the documents is recorded. The date and version of the accepted Terms and Policy are visible later in Settings → General, the "Acceptance of legal documents" block. It is read-only: this is evidence, not a setting.
Signing in#
- Open
/login, type in your e-mail and password. - Or press the Google sign-in button — Google renders it itself, and for a returning person it is personalised, with a name and an avatar.
- Or sign in with a device code — see the section below.
Useful details:
- There is no "remember me" checkbox. The session is kept in the browser and lives until you press "Sign out" in the sidebar or until it is revoked. Signing out in one tab closes the session in all of them.
- Someone who is already signed in is quietly moved from the sign-in page into the panel.
- At the bottom of the form there are links to the Terms and the Policy: by signing in, you accept them.
- Demo data. Any panel address with the
?demoparameter opens a demonstration storefront with ready content; someone who is already signed in stays in their own account.
Password recovery#
- On the sign-in page press "Forgot your password?" —
/forgot-passwordopens. - Enter the account e-mail. The letter with the code is sent in the language of the page you requested it from.
- A couple of seconds later
/reset-passwordopens with the address already filled in — type the code from the letter and the new password twice. - After a successful reset the system takes you back to the sign-in page itself.
Requirements for the new password: 8+ characters, an upper-case and a lower-case letter, a digit, a special character.
Sign-in by code and QR#
Codes are for places where typing a login and a password is inconvenient or unsafe: a menu tablet, an order monitor, a kitchen screen, a till, a shared terminal.
| What | How it looks |
|---|---|
| Where to create a code | "QR codes" → the "Devices" tab (/client-codes?tab=devices): the code, a sign-in link of the form /login?code=…, instructions and a QR image. In detail — QR codes and device codes |
| How to sign in | The "Scan QR" button on /login, the address /login?code=…, or the thin page /qrlogin?code=… |
| Protecting a code | If the code is protected, the system asks for a PIN (4 digits) or a password |
| Codes for the panel itself | The third tab of the section — "Admin sign-in"; it is open to the owner and to a role that has been given the "Settings" section |
| How to revoke | Delete the code in the same section — the link stops working |
⚠️ A code session is deliberately limited. It does not give full access to the account and may be locked onto a single target page (the order monitor, for example) — so a shared tablet in the dining room does not turn into a full owner sign-in.
Handing the account over to another e-mail#
Where: Settings → Access (/settings/access), the e-mail change and account handover block.
- Enter the new address and confirm the action in the window with the warnings.
- A letter with a link goes to the new address.
- The recipient opens
/confirm-email-transfer, sets their own password and gets access to the account with all its data.
The link is one-time and has a limited lifetime: an expired or foreign token shows an error screen — then start the handover again. This is a handover, not a copy: the old address loses access.
⚠️ Limitations: on cenaly.ru there is no handover block at all, and anyone who signed in with a QR code cannot change the e-mail.
Support access#
A support agent cannot enter your account without your consent — access is off by default.
- It is switched on in Settings → Support access (
/settings/support-access): a consent toggle plus the scope — "view only" or "view and edit". - The same place shows the history of consents (when granted, changed, revoked) and the log of sessions: the agent's e-mail, the scope, the start and the end, an "active" mark.
- Revoking consent kills the session that is running, not only the next one.
- The agent signs in under their own name, so an intercepted link is useless on its own.
- An implementation partner is a separate case with its own rules; they ask for access and you grant it. The details — Security and data.
On cenaly.ru there is no log of support sessions: the circuit has not been ported there yet.
Staff with their own logins#
There is one account and many people in it. An employee can be given their own sign-in to the panel (e-mail and password), or a 4–6 digit cashier PIN for a shared terminal is enough; a person without a login is a "resource" (a specialist in the appointment book, for example). What they see is decided by the role tier and the job title. The limit is 30 employees per account.
Everything about roles, invitations, password resets and deactivation — Staff and shifts.
Deleting the account#
There is no "delete account" button in the panel — deletion goes through a request, so that an accidental click does not destroy business data.
- Export your data first — Data export. PINs, integration keys and tokens, and passwords are not included in the archive.
- Then write to support from the account owner's address — How to get help.
The request is fulfilled within 30 days of being confirmed. After the deletion there is nothing left to take, so the export comes before the request, not after.
Limitations#
- Two-factor sign-in is in preparation — with an authenticator app (SMS codes are not planned); it is not there yet. Protect the sign-in with a long password and separate staff logins instead of one shared password for everybody; on tablets and shared screens use device codes with a PIN.
- Google and Facebook only work on the cenaly.com and cenaly.com brands; VK ID, Yandex ID, Sber ID, Gosuslugi, Mail and Odnoklassniki — only on cenaly.ru.
- Registration from a printed QR code is available on cenaly.com and cenaly.com; signing in with a code works in both clouds.
- On cenaly.ru there is no account handover to another e-mail and no log of support sessions.
- There is no self-service account deletion in the panel (see above).
- One person can work in several accounts with a single password of their own — when you create an employee with an already registered address, connecting the existing user is offered.
Troubleshooting#
| Symptom | Cause | What to do |
|---|---|---|
| The confirmation code never arrived | The letter is in spam, or the address has a typo | Check the "Spam" folder, then request the code again; if there is a typo, register again with the correct address |
| There is no "Sign in with Google" button | The Google script did not load (blocker, network) | Sign in with your e-mail and password: the fallback button that appears after 3 seconds does not complete the sign-in right now |
| The sign-in page hangs | A stale session cache in the browser | Press "Clear cache and retry" on the sign-in page and sign in again |
| The sidebar renders, but every section is refused | The session was closed in another tab, or it was revoked | Reload the page and sign in again |
| A device code does not let you in | "Code expired" / "invalid code" / "the code exists but is not connected" | For expired and invalid ones create a new code in "QR codes"; an unconnected one will offer registration with it |
| The handover link complains | The token is one-time and has a limited lifetime | Start the handover again from Settings → Access |
| An employee cannot sign in | No "sign-in to the admin panel" checkbox, or they are deactivated | Check their row in /staff |
FAQ#
Can we work on a tablet without typing a password? Yes, that is exactly what device codes are for: create a code in "QR codes" → "Devices" and open the sign-in link with it on the tablet.
What happens to the data if I change the e-mail? Nothing is lost: the whole account moves to the new address. Access from the old address disappears.
I signed in with Google — can I then sign in with a password? Yes. Set yourself a password in Settings → Access; the old password is not asked for in that case, and both methods work afterwards.
How long does a session live? It renews itself while you use the panel. It is closed by the "Sign out" button in the sidebar — in all browser tabs at once.
Is there sign-in by SMS code or one-time passwords? No. The sign-in methods are a password, the brand's social provider, and a device code. Two-factor sign-in with an authenticator app is in preparation; we promise no dates, and for now the strength comes from a long password and from every employee having their own login.
How do I take the account back from an administrator who has left?
If they were an employee — deactivate or delete their row in /staff. If the account is registered to their address — hand the account over to your own e-mail.
What does a support agent see when I switch access on? Exactly the scope you chose, and only while the consent is on; every session goes into the log. In more detail — Security and data.
Related articles#
- Account and location settings — where language, currency, country, access and export live
- Security and data — where the data is stored and who has access to it
- Staff and shifts — logins, roles, cashier PINs
- QR codes and device codes — sign-in codes for tablets and screens
- Data export — take everything in one archive
- Subscription — plan, balance and invoices
- How to get help — where to write if you cannot sign in