# Orders and fulfillment

Guest product orders with server-priced line snapshots, pickup/delivery, verified payments, customer tracking and paid-only fulfillment.

## Install

Use the verified installer in the website container. It installs dependencies, checks checksums, and refuses to replace customer changes:

```sh
python /opt/runalio/catalog_install.py orders
python /opt/runalio/catalog_install.py --status
```

Review the preview and click Publish to promote backend code and pages. Production data remains separate.

To undo the last installation before publishing: `python /opt/runalio/catalog_install.py --rollback`.

## Settings

The customer enters these in Runalio, Settings → Website modules → this module (never in files or chat):

| Name | Required | Secret | Purpose |
|---|---|---|---|
| `ORDER_FULFILLMENT` | no | no | pickup, delivery or both. Defaults to pickup. |

## What the customer needs to do

- Configure real active products in server/config/catalogue.json through the coding agent.
- Configure Stripe and its required signed webhook. Add site/orders.js with a data-runalio-orders element.
- Manage paid orders in Business admin. Cancellation does not itself refund a payment.

## Administration and data

Business admin opens from the portal Settings. Managed websites use portal team membership and same-origin mutation checks. Customer data stays in the website SQLite database and participates in consistent backups. Agent changes to source and page snippets remain drafts until Publish. No customer credentials are embedded in pages or chat.
