Recent Shipments
| Shipment ID | Customer | Status | Hold | Est. Value | Action |
|---|
Kit requests from the websiteNewest first · each request shows where it came from · “Create customer + kit” copies it onto a new customer and marks it converted
These are the forms people sent from the website (pre-launch: test entries only until go-live). Sandbox and Live share this list; a request converted in Sandbox is marked as such and can still be converted in Live. The customer’s consent on the site covers contact and the Privacy Policy — confirm the Terms and the ownership statement with them before the kit goes out.
| Received | Name | Contact | Where from | Value band | What they have | Status | Actions |
|---|
Customers
| Customer ID | Name | Phone | Country | KYC | Rate | Payment | Shipments | Actions |
|---|
Shipments
| Shipment ID | Customer | Items | Au (g) | Ag (g) | Est. Value | Rate | Status | Hold | Actions |
|---|
Package IntakeScan barcode or type Shipment ID to begin
Customer CallsCall each customer and walk through their offer item by item
AMPCOR Outbound
Select shipments that have cleared their 15-day hold and customer has accepted the offer. Despatch every Monday, insured, via the carrier — no parcel above the insured box cap, no batch above the insured shipment cap (split into parcels). AMPCOR logs Córdoba police portal Tuesday. 7-day AMPCOR hold. Refine following Tuesday.
Ready for despatch
| Shipment ID | Customer | Items | Au (g) | Ag (g) | Est. Value | Hold Released |
|---|
Batches sent to AMPCOR
| Batch ID | Sent | Shipments | Au (g) | Ag (g) | Advance Paid | Balance Paid | Status | Actions |
|---|
Customer Payments
Pay sellers by bank transfer once the refiner's settlement for their lot is in and a second authoriser has approved. After the transfer has gone: Mark Paid, print the final statement (🧾) and send the payment message (📲) — nothing is sent automatically.
Video LibrarySearch all intake recordings by shipment, customer, or date
Recordings
| Video Filename | Shipment ID | Customer | Date Received | Items | Google Drive | Copy Filename |
|---|
📁 Videos save to: Google Drive → OroFair → Videos → 2026
Filename format: OF-00042-K7M3PQ-VIDEO-2026-07-10.mp4 — always use the exact filename shown above so recordings can be found by shipment ID.
Filename format: OF-00042-K7M3PQ-VIDEO-2026-07-10.mp4 — always use the exact filename shown above so recordings can be found by shipment ID.
Kit Re-engagementCustomers who requested a kit but have not sent their items
Unconverted kits
| Customer | Shipment ID | Kit Sent | Days Waiting | Sequence Stage | Actions |
|---|
Reports & Documents
🚔
Police Log
Weekly transaction list for portal submission
📊
Export All Data
Full CSV for accounting
Customer documents live on each shipment row, so they always carry the right figures, gates and wording: 📨 Offer (the Formal Offer — link, code, print, confirmation), 🧾 Statement (indicative or final), the 📲 messages (kit on its way, parcel received, payment sent, items on their way back) and the kit sheets on a Kit Sent row. The AMPCOR despatch note is produced on the AMPCOR tab when a batch is generated. The old Documents cards (offer letter, receipt, remittance advice, tracking preview, terms template) were retired on 22 Sep 2026 — they printed wording the decisions since 9 Sep had replaced.
Operating Manual
📖 In-app mirror of the controlled manual. Maintained by James Canepa (CLO). The signed master governs — this copy is for reference and the block alarms link into it.
Loading…
Audit TrailAppend-only compliance log — every state change, timestamped and attributed
| Timestamp (UTC) | User | Entity | Action | Detail |
|---|
Settings
Environment — Sandbox vs Live
The app starts in Sandbox by default. Sandbox and Live keep completely separate data — practise freely in Sandbox; Live stays clean until you switch. Switching applies to everyone signed in, and is recorded on the environment record.
Pricing — jewellery & scrap (decisions 9–14 Sep 2026)
Chain per item: assayed fine content − processing charge = recovered content × rate × reference price = gross; net = gross ÷ (1 + ITP); ITP = net × rate. The customer receives the net. Effective: gold 0.95 × 0.90 = 85.5% gross / 82.21% net; silver 0.92 × 0.85 = 78.2% gross / 75.19% net.
Gold processing charge% of assayed content (a fixed commercial charge, disclosed on the offer — not overridable; never described as metal lost or a cost passed on)
Silver processing charge% of assayed content (a fixed commercial charge, disclosed on the offer — not overridable; never described as metal lost or a cost passed on)
Gold rate (global default)% of recovered content (the published floor)
Silver rate (global default)% of recovered content (the published floor)
Pricing — recognised coins & bars (bullion)
Bullion gold rate% of marked fineness × verified weight — no charge line
Bullion silver rate% of marked fineness × verified weight — no charge line
Recognised = coins from sovereign mints and bars from LBMA-type refiners (the LBMA Good Delivery list or an equivalent recognised standard, e.g. LPPM), per the internal annex of accepted names (decision 14 Sep 2026); entered as “Bullion — gold/silver”. Anything else is paid as metal on the jewellery chain. The website publishes 95% / 88%; keep these in step. Each equivalent standard on the recognised list needs Board approval (decision 15 Sep 2026): record the approved list under a dated version in “Recognised-bullion list version” below — it is printed on every offer.
ITP (transfer tax) — applies to every purchase, bullion included
Decision 15 Sep 2026 (D5): the Buy-Now figure is shown net of ITP with the tax itemised, provisionally — it stays marked TBC in the app until Contasult's written confirmation of the method is dated in Settings → Compliance.
ITP rate% — base is the net price (net = gross ÷ 1.04)
Untick only on a written instruction — OroFair then absorbs the tax
Reference price (final settlement)
The final amount is struck at the Reference Date (refining day; for recognised coins and bars, the day the acceptance is confirmed — decision 15 Sep 2026; 60-day longstop from acceptance) using the LBMA Gold Price PM / LBMA Silver Price in EUR — converted at the ECB euro reference rate if published in USD. Enter it per shipment via “Ref price” on the Shipments tab. The daily spot below is only for indicative offers.
Buy-now — INTERNAL planning pre-fill
Gold (internal)% of fine content, net of ITP — pre-fills the operator's euro field only
Silver (internal)% of fine content, net of ITP — pre-fills the operator's euro field only
Buy-now is an individual fixed euro amount per lot, always editable. No rate is ever shown to the customer.
Formal offer & acceptance (terms §16–18)
Today the site answers at https://orofair-web.web.app/track.html — orofair.com is not pointed at it yet. The launch gate checks that this address answers.
Every Formal Offer carries this version and its adoption date and the dated versions of Schedule 1 and Schedule 2 (terms §1/§36/§38: “the version of these Terms and the dated version of each Schedule identified in your Formal Offer apply to your Transaction”); the acceptance record copies all three from the offer (each max 16 characters; blank allowed while a schedule is still draft). The recognised-bullion list version is printed on offers beside the bullion note; each equivalent standard added to that list needs Board approval (decision 15 Sep 2026) — bump the version when the Board approves a change. Change it only when James issues a new version. While the version contains “draft”, Issue formal offer is blocked unless the sandbox-only box above is ticked. The link sent to the customer is
<tracking page>?kit=<shipment>&offer=<offer id>; the acceptance code goes separately by SMS/WhatsApp.Storage & unclaimed items (terms §25 — decision 15 Sep 2026: a percentage of the tested value, no cap)
Custody & insurance charge% per month of the lot's tested metal value, counted daily (÷ 30), from day 31 after the first Formal Offer until the day of acceptance — no cap
Free storagedays from the date the FIRST Formal Offer is sent (§25.1)
Reminder due afterdays without an effective instruction (§25.3 — a reminder always precedes the final notice)
Final notice due afterdays without an effective instruction (§25.3, “approximately 90 days”) — only once a reminder has been sent
Final notice periodfurther days to respond (§25.3, at least 14) — then Realisation with a second authoriser (§25.4)
A small custody and insurance charge, worded gently to the customer: it is there to prompt a decision, not to earn money. It is counted on the lot's tested metal value (fine content for coins and bars) at the reference price on the day of the first Formal Offer — frozen on the shipment when that offer is issued, so the charge never moves with the market — and it stops on the day of acceptance or on the day the customer asks for the items back (a clear instruction in writing or on a recorded call, recorded with “↩ Customer asked for items back” in the Storage window; a decline counts — decision 22 Sep 2026). Days of our own delay in repacking and despatching are never charged. The charge is computed, never taken automatically: it accrues on the shipment record, is shown on the statement, and is deducted from the amount payable only once it has been disclosed to the customer (Formal Offer, reminder, final notice or statement). The reminder (about day 60) and the final notice (about day 90, giving 14 more days) say the offer has lapsed and is reinstated at the same rate on request, and quote the figure the customer was offered. A dataset migrated from the earlier “€1 per lot per day, capped” basis keeps any fee already accrued as a frozen figure and keeps the old rate as
legacyStorageFeePerDay for audit. Timers are badges on the shipments and an “Attention” list on the dashboard — nothing runs in the background.Daily Spot Prices — indicative daily price; final settlement uses the LBMA reference price recorded on the shipment
Gold spot (€/g)
Silver spot (€/g)
AMPCOR Terms
Gold — discount per gram€/g below spot
Silver — discount %% below spot
Advance payment %% on receipt + police logging
Compliance Controls — Operating Manual v2 (draft with James Canepa)
Manual v2 is with James Canepa for the clean v3. The decisions of 14 Sep 2026 are applied here: the item goes on the police register when the customer accepts and the 15-day hold follows; video-witness receipt is the standard; the touchstone is a pre-purchase test; the fixed deduction is the processing charge. All reversible; Appendix T numbers pending Board sign-off.
Statutory hold (days)calendar days
Hold clock starts fromDecision 14 Sep 2026: the item goes on the register when the customer accepts; the 15-day hold counts from the weekly police submission that follows — never from the day the parcel arrived. The §25 storage-fee pause uses the same dates.
Police submission weekdayThe one day/week the comisaría accepts — hold can't start before this day
Assay methodThe touchstone is a pre-purchase test, done before the offer and not gated by the hold (decision 14 Sep 2026); destructive tests only after the hold expires, with the seller's recorded consent
Melt notice (days)RD 197/1988 art. 96
Receipt witness — video-call standard (Manual §8 step 4, Appendix T; decisions 14 and 15 Sep 2026)
Receipt mode
Comma-separated names of the people who may witness a receipt (by video) or be the second operator (physical). Decision 15 Sep 2026 (D2): the video route stays the standard and OroFair does not go live on it until Aon confirms in writing that the policy accepts it — the TBC pill above clears when that date is recorded below. Intake cannot complete without a named witness / second operator who is not the person opening the parcel; the continuous recording is the control in both modes. A mode change is logged as an amendment. Leave the names blank to reset to Patrick, Con Lehane, James Canepa.
Written confirmations before launch (James's round two; decisions 15 Sep 2026) — each blank line is a launch-gate blocker with a TBC pill
Dates only; the letters live in Drive → Legal & Compliance. Tax: the Buy-Now figure is shown net of ITP with the tax itemised (D5) — provisional until Contasult's letter. Insurer: video-witness receipt (D2). Police: register trigger on acceptance, touchstone before the offer, Buy-Now payment before the hold (D3/D4) — the buy-now-before-hold switch above stays off regardless until the answer says yes. Refiner: the Formal Offer states that the Standard Settlement route depends on settlement from the approved refiner (D6) — the customer document never shows a TBC marker; this pill is for the app only.
Hard-coded gates (Manual §4.2) — tick = enforced
Offer to buy — buy now (discounted, operator-priced)
Suggested discount (pre-fills the offer; operator sets the final amount per deal)%
Buy-now unlocks only after lab testing + CDD/KYC/AML complete; the operator enters the fixed euro amount on the Formal Offer (shown side by side with the standard route), the customer accepts it separately on the tracking page, and payment still needs a second authoriser.
Paying Buy-Now before the 15-day hold expires — the three conditions (Manual v3.3 §11.2; decision 21 Sep 2026)
All three dates must be on file before any Buy-Now payment is made inside the hold; until then a Buy-Now payment waits for the hold to clear, exactly like a standard payment (the customer can still accept Buy-Now and the amount stays fixed). A positive police reply is not a condition unless the legal assessment says so. Every Buy-Now also needs the seven checks on the shipment (👤 Buy-Now checks), and above the approval figure a second approval by Con or James — never the person who made the offer — plus one piece of supporting evidence and the weekly police filing containing the item. Beyond the ceiling, new Buy-Now payments wait.
Board value limits (Appendix T): per parcel = the insured box cap (Business details, €20k default; envelope €5k; shipment €60k — Aon to confirm) · second valuation/senior approval €20k · overnight stock €100k · vault €200k · refiner batch €100k · assay variance tol. 3%. Edit the others in code/config once the Board signs off.
Business Details — the entity printed on offers, statements, receipts and the police log
Decision 10 Sep 2026 (Q22): everything is issued in the name of OroFair S.L.; Hisnoha Investments S.L. is not named anywhere in the app. The NIF, once entered, is logged as an amendment. Offers and statements are blocked until both the NIF and the registered office are entered.
Contact block — added to the end of every customer message and print
One address and one number, the same as the website. Leave the WhatsApp number blank until there is a business number — messages then give the e-mail only.
Payments to sellers
Sellers are paid by bank transfer. The provider's name, once chosen, appears only inside the app (payment rows, the export) — never on a customer message or document (decision 22 Sep 2026).
Logistics — Paul Charrington: insurance and carriers (decisions Q16 and 14 Sep 2026; Aon figures of 11 Sep)
Envelope up to the envelope cap of expected value; box up to the box cap; above the box cap the operator splits the lot into parcels (flagged at intake and on despatch) or books the high-value carrier — the customer is never told why. Insurer and carrier are named on shipping documents and the website only, never in the terms; labels never carry a value, a brand or the insurer's name.
Police registration (launch gate)
App Check (launch gate)
Console: App Check → APIs → Cloud Firestore → Enforce, only once "Unverified requests" is near 0% for a few days after this app version is deployed. Also add the ops hosting domain to the reCAPTCHA key's allowed domains. Record the date here to clear the Launch-gate line.
⚠ Insurance excludes parcels whose label suggests valuable contents, and discretion means not revealing the premises. Keep the parcel return name/address plain — no "OroFair", "gold", "precious metals", "joyería" or the building name. Businesses in the Parque Joyero write the street form instead: Carretera Palma del Río km 3,5, fábrica or nave number, 14005 Córdoba (Aon, 21 Sep 2026). The app refuses to save or label with a name or address containing such a word.
Carrier API — Correos (stage 7; shared by Sandbox and Live; the secret is never entered here)
Not tested yet.
Sandbox mode calls the test environment, Live calls production; the function decides from the mode, not the browser. Live labels are refused until the neutral return address and the NIF are set. Two credential pairs (Correos "Uso OAuth 2.0" v1): the Correos ID application pair gets the bearer token (scope = the API); the API pair from the developer portal goes in the client_id / client_secret headers once access is approved. Secrets go into Secret Manager only: firebase functions:secrets:set CORREOS_CLIENT_SECRET and CORREOS_API_CLIENT_SECRET (value pending until Correos issues it). Config saved here is logged in the Audit.
Parcel condition check at intake (insurance evidence)
Defaults 5 g / 1% — deliberately tight (5 g of gold is worth hundreds of euros); widen only once Paul's dummy parcels show how much Correos' sorting-machine weight drifts. Differences over 2 g / 2% are still flagged amber below the stop line. The check passes when the received weight is within the larger of the two tolerances of the origin weight, the seal is intact, the packaging is undamaged and (if required) the bag number matches. A failed check stops the intake; only an admin who is not the operator can override it, with a reason, and the override is audited.
Weigh one empty kit of each type and enter it here — the tare is used to reconcile the received parcel weight against the items on receipt.