CLETUS MOBILES — SELF-HOSTED PACKAGE Runtime: Node.js 22+ (24 also supported). Startup: server.js. No npm dependencies. Namecheap Passenger manages the process and port. Do not create your own proxy or change .htaccess in the domain document root unless Namecheap support instructs you. Application root: cletus-app in the hosting account home, outside public_html. Private storage: sibling cletus-app-private-data. Optional cPanel environment variable CLETUS_DATA_DIR overrides its absolute location. Keep this outside every public domain document root. Local run: PORT=3000 node cletus-app/server.js Local setup: http://localhost:3000/setup Production: cPanel Application Mode = Production; use HTTPS through cPanel. Storage is durable, file backed, and included in normal hosting file backups. Each object is an atomic JSON envelope with base64 bytes and content type metadata. No Cloudflare account, R2 bucket or SQL database is required. Multi-process mutations use a filesystem lock. The original business logic lives in store.mjs and all built-in images/fonts are embedded. Backups: back up cletus-app and cletus-app-private-data together. Email decryption depends on the key in installation.json. Do not regenerate this key for an existing installation. No records have been migrated from the previous hosted preview. Password reset: using authenticated cPanel File Manager, upload reset-admin.js from this ZIP into cletus-app if it is not already there. Create a text file named new-admin-password.txt inside cletus-app-private-data containing a NEW password of at least 12 characters. In cPanel's Node app panel, use Run JS Script (if available) or its application virtual environment terminal to run node reset-admin.js. The script changes only the password hash and removes the temporary password file. Restart the app. Do not delete installation.json to reset a password: that also replaces the email encryption key. Email: Resend API integration is preserved. Enter a real verified sender and API key in Admin > Email Settings. The key is encrypted at rest and never returned to the browser. Provider acceptance and delivery checks are separate. An accepted email does not prove inbox delivery. Real inbox delivery requires the shop's DNS/sender setup and a successful test from this deployment. Phone support/WhatsApp: +260976197233. Checks: open each customer page; submit a test request; confirm in admin; edit a test product; record a test payment; download a PDF; configure and test email. Remove or clearly mark test records before opening to customers. This ZIP is a new installation with empty customer records.