Connection checklist
Everything below runs on placeholders today. The flow is complete and clickable without a single secret configured.
Lovable Cloud (accounts, orders, intake, evidence)
Turn on Cloud and the local order store becomes real tables: orders, intake_answers, drafts, revisions, evidence_events, voice_samples. Row-level security scopes every row to its owner; partner answers sit in their own rows so neither partner can read the other's.
Stripe
Stripe-hosted Checkout or Payment Element only — no card data touches this app. Store customer id, payment intent id, charge id, receipt url and the Radar outcome on the order. Add a webhook at /api/public/webhooks/stripe to record payment_succeeded, refunds and dispute events. Hold fulfilment for any order marked elevated or hold.
Resend
Use info@toastgiver.com as the customer-facing sender and reply-to placeholder unless the provider requires a different verified technical sender. Magic links, partner intake links, preview notices, receipts, delivery and support replies all keep info@toastgiver.com as the public contact. Log every send result onto the order as dispute evidence.
OpenRouter
All writing, personalisation, QA and voice-sample transcription route through OpenRouter — never the OpenAI API directly. Keep the key server-side; the browser never sees it. src/lib/toastgiver/generate.ts is the seam to replace.
Google Analytics & Google Ads
Add after the end-to-end flow is proven. Track category selection, intake completion, preview view, preview retry and checkout as the funnel.
Markifact
Acquisition side, last. Do not wire before a real order has gone from intake to delivery without intervention.
Data kept locally for now
Orders and their evidence trail are stored in this browser only. They will not follow you to another device until Cloud is connected.