sbskubase

Privacy Policy

skubase (“skubase,” “we,” “our”) is operated as an independent, founder-led company. This policy describes what we collect, why we collect it, who we share it with, and your rights.

What we collect

When you start a free trial or create an account we collect: your email address and the source page you signed up from. When you connect a Shopify store we collect: product catalog, inventory levels, vendor names, and order line-item history necessary to compute reorder recommendations. When you upload a ShipStation or Stocky CSV, we ingest only the rows in that file.

Shopify order imports retain order and line-item identifiers, product references, quantities, prices, and order dates. They do not request customer names, customer email addresses, phone numbers, or delivery addresses. We also store your app account and Shopify connection details to authenticate access to your workspace.

Server logs include standard request metadata (IP, user agent, path, status code) for the purpose of operating the service. Vercel Analytics and Vercel Speed Insights are deployed in privacy-preserving (cookieless, no personal identifiers) modes.

How we use it

We use your data only to operate the service: rank reorder actions, score suppliers, surface dead-stock plans, deliver alerts you configure, and respond to support requests. We do not sell your data. We do not train AI models on your store data. We do not share your data with advertisers.

Sub-processors

We rely on the following sub-processors to operate the service. Each receives only the minimum data necessary for its function:

Retention and deletion

You can delete your account and associated data at any time by emailing info@skubase.io. We will purge your data from production within 30 days. Aggregated, anonymized metrics may be retained for service operation.

Shopify privacy requests are processed for the store that issued them. Customer redaction removes matching retained order records; shop redaction removes the uninstalled workspace and its associated production records. Customer access requests are available to the merchant under Privacy Requests in the app. Uninstalling revokes access immediately; Shopify sends the shop redaction request separately. Delayed requests for an earlier installation do not erase a subsequently reinstalled workspace.

Your rights

You have the right to access, correct, export, and delete your personal data. Contact info@skubase.io for any such request. EU residents have rights under GDPR; California residents have rights under CCPA; we honor both equivalently for all users.

Cookies and storage

Embedded Shopify access uses short-lived Shopify session tokens and does not require third-party cookies. Browser storage can remember interface preferences; standalone website sign-in uses a session cookie. To understand where merchants find Skubase and where onboarding needs improvement, first-party storage retains a random visitor identifier, landing-page path and campaign attribution for up to 30 days. These events can be linked to your store after sign-in. This measurement is skipped when your browser sends Do Not Track. We do not store URL query strings or use third-party advertising cookies for this measurement.

Security

Data in transit is encrypted via TLS. Shopify connection tokens are kept on the backend and are not sent to the browser. Access to store records is scoped to the authenticated workspace. Contact us for further details about hosting safeguards and data retention.

Changes

If this policy changes materially, we'll notify all registered users by email at least 30 days before the change takes effect. Minor clarifications and typo fixes will be reflected here without notification.

Contact

Questions about this policy: info@skubase.io.

Privacy Policy — skubase · skubase