Privacy Policy
What personal data Inventrixo handles, where it is held, who else touches it, and what you can require of us.
Last updated 11 September 2026 · Inventrixo
Draft — pending legal review
This document was prepared from how the Inventrixo service is actually built, but it has not yet been reviewed by a qualified data-protection lawyer. It is published for review and is not yet a binding statement of our practices. Please do not rely on it when making a purchasing or compliance decision — contact us at privacy@inventrixo.com and we will answer directly.
1.Who we are
Inventrixo is a point-of-sale, inventory and repair-tracking service for retail and device-repair shops. It is offered as a web application and as a desktop application that runs on the shop's own computer.
The service is operated by Inventrixo. For anything in this policy you can reach us at privacy@inventrixo.com.
2.Two different roles — and why it matters to you
Under UK and EU data-protection law there is an important distinction between deciding how personal data is used (a controller) and merely handling it on someone else's instructions (a processor). Inventrixo is both, depending on whose data is in question.
| Whose data | Our role | What that means |
|---|---|---|
| The shop and its staff — the people who sign in | Controller | We decide what account data we need in order to provide and bill for the service. This policy governs it. |
| The shop's own customers — names, contact details, repair history | Processor | The shop decides what to record and why. We only hold and process it to run the service for them. The shop is the controller, and its own privacy notice governs it. |
So if you are a customer of a shop that uses Inventrixo and you want your data corrected or erased, the shop is who to ask — they control it, and they can do both from within the product. If they need our help to action your request, we will provide it.
Shops acting as controllers need a written processor agreement from us. That is our Data Processing Agreement, which forms part of our terms.
3.What we collect, and why
We collect only what the service needs in order to work. Specifically:
| Data | Why | Lawful basis |
|---|---|---|
| Name, email, phone, password (stored only as a hash) | To create your account, sign you in, and contact you about the service | Performance of a contract |
| Shop name, address, country, tax settings | To configure the product for your market — currency, tax mode, invoice details | Performance of a contract |
| Business records you enter: products, sales, expenses, suppliers, repair tickets, customers | This is the service. We hold it so that you can use it | Performance of a contract |
| Subscription and payment status | To take payment and give you access to what you paid for | Performance of a contract; legal obligation for tax records |
| Sign-in times, and an activity log of actions taken in your account | Security, and so you can see who did what in your own shop | Legitimate interests — securing the service and resolving disputes |
| A one-way hash of your computer's characteristics, when you start a desktop trial | To stop the same machine taking repeated free trials | Legitimate interests — preventing abuse of a free trial |
| The text you type into an AI feature, and the shop context needed to answer it | To generate the answer you asked for | Performance of a contract, on your instruction each time |
We do not use analytics, advertising or tracking software of any kind. There is no Google Analytics, no advertising pixel, no session recording, and no third-party script that profiles you. We do not sell personal data, and we do not share it for advertising.
5.The desktop app keeps your data on your computer
The desktop application is local-first by design. Your shop's records — products, sales, customers and repairs — are stored in an encrypted database file on your own computer and are not uploaded to us.
That file is encrypted with AES-256-GCM, with the key strengthened using PBKDF2-SHA256 at 210,000 iterations. You can optionally add a passphrase of your own. You can export everything, or erase everything, at any time from Settings › Privacy & data.
The desktop app contacts our servers only for these things, and nothing else:
- Checking your licence or subscription status
- Registering the start of a free trial, to prevent trial abuse
- Answering an AI request, if and when you invoke an AI feature
- Checking for and downloading application updates
If you use the web application instead, your records are stored on our servers as described below. Which of the two you use is your choice.
6.Where your data is held, and international transfers
This section matters most if you are in the UK or the EU, so we will be direct about it: our servers and database are located in the United States (AWS US East, Northern Virginia).
If you are in the UK or the EU, using the web application therefore involves transferring your personal data outside your own jurisdiction. The United States does not have a general adequacy decision, so such transfers rely on a safeguard mechanism — the UK International Data Transfer Addendum, or the EU Standard Contractual Clauses, together with an assessment of the transfer. Those safeguards are set out in our Data Processing Agreement.
If you would prefer your shop's data never to leave your premises at all, use the desktop application. It stores everything locally, as described above, and it is the option we would point a privacy-conscious shop towards.
We do not currently offer a UK or EU hosting region for the web application. If that changes we will say so here, and tell existing customers before it takes effect.
7.Who else processes your data
We use a small number of service providers to run Inventrixo. Each is bound by contract to process data only on our instructions. This is the complete list — we do not add one without updating this page.
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Application hosting and content delivery | United States, with a global edge network |
| Neon Inc. | Managed PostgreSQL database — where account and shop records are stored | United States (AWS us-east-1, N. Virginia) |
| Lemon Squeezy LLC | Subscription billing. Acts as merchant of record and handles all card data | United States |
| Anthropic PBC | AI assistant and product suggestions, when a user invokes an AI feature | United States |
| Resend Inc. | Transactional email — account, billing and notification messages | United States |
| Twilio Inc. | SMS notifications, where a shop enables them | United States |
On AI features specifically: a request is sent only when a user actively invokes one, and it carries the question plus the shop context needed to answer it. Our AI provider processes it to produce a response and does not use it to train their models. If you would rather no data reached an AI provider at all, do not use the AI features — every other part of the product works without them.
On payments: card details are entered on our payment provider's own hosted page and are handled by them as merchant of record. We never see or store your card number.
8.How long we keep it
| What | How long | Then what |
|---|---|---|
| Shop records (products, sales, customers, repairs) | For as long as the account is active | Deleted with the account, or on request. Erasable at any time from Settings. |
| Account and user records | For as long as the account is active | Deleted on account closure or on request. |
| Billing records | As required by tax law in the relevant jurisdiction (commonly 6–7 years) | Retained by our payment provider as merchant of record. |
| Audit and activity logs | For the life of the account | Deleted with the account. Kept as a security and dispute-resolution record. |
| Desktop trial device records | Indefinitely, as a hash | A one-way hash of a device fingerprint, kept to stop the same machine taking repeated free trials. It cannot be reversed to identify a device or person. |
You can delete your shop's records yourself at any time — in the desktop app from Settings › Privacy & data, and in the web app by asking us to close your account. Deletion is permanent.
9.How we protect it
- Passwords are stored only as salted hashes. Nobody at Inventrixo can read your password.
- Two-factor authentication is available on web accounts, and we recommend enabling it.
- All traffic to and from the service is encrypted in transit (TLS).
- The desktop database is encrypted at rest with AES-256-GCM, and a tampered file is detected rather than silently accepted.
- Access to production systems is limited to those who need it to operate the service.
- Staff accounts within your shop have roles, so you can limit what each employee can see and do.
No system is perfectly secure, and we would rather say so than imply otherwise. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly where there is a risk to you.
10.Your rights
If you are in the UK or the EU you have the rights below. We honour them for everyone, wherever they are, because drawing that line by geography would be mean-spirited.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion, where we have no overriding obligation to keep it.
- Portability — your data in a structured, machine-readable format. The desktop app does this for you in one click, as JSON plus a spreadsheet per table.
- Restriction and objection — to limit or object to particular processing.
- Withdrawing consent — where we relied on consent, at any time.
Write to privacy@inventrixo.com and we will respond within one month. We will not charge you, and we will not ask why.
You also have the right to complain to a data-protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EU it is the authority for your country. We would appreciate the chance to put things right first, but that is your choice, not a precondition.
11.Children
Inventrixo is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.
12.Changes to this policy
If we change how we handle personal data we will update this page and change the date at the top. Where a change materially affects you — a new sub-processor, a new purpose, a new data location — we will tell account holders by email before it takes effect, rather than relying on you to re-read this page.