InventoryFlo
Billing & PlanSign in

Privacy Policy

Last updated: 24 September 2026

1. Who we are

InventoryFlo (the "Service") is operated by MANARA DIGITAL LTD ("we", "us", "our"), the company publishing the InventoryFlo apps and website, a company registered in England and Wales.

For any privacy question or to exercise your rights, contact contact@inventoryflo.app.

2. Scope

This Policy describes the personal data we process when you visit our website, sign up for an account, or use the InventoryFlo web app or mobile app. It applies to data processed in our capacity as data controller (for account, billing, and support data).

When you (our customer) use the Service to record your own business' inventory, suppliers, and staff activity, we act as a data processor on your behalf for that operational data.

3. Personal data we collect

3.1 Account data

  • Name, email address, and password (stored as a salted bcrypt hash — we never see or store the plain-text password)
  • Organization name and your role/permissions within it

3.2 Content you add to the Service

  • Inventory data: items, SKUs, stock levels, lots, suppliers, purchase orders, stock counts, and audit trail of who changed what
  • Item photos you choose to attach, captured or picked from your device's camera/photo library
  • Barcode values scanned with your device camera. The camera image itself is processed on-device to decode the barcode and is never uploaded — only the decoded barcode text is sent to our servers, the same as if you had typed it

3.3 Technical data

  • IP address and basic request metadata (for security and rate-limiting), retained in server logs
  • Device/browser type, so the app can serve the right layout

3.4 Communication data

  • Support emails and any information you choose to include in them

We do not run any advertising, cross-app tracking, or third-party analytics SDK in the InventoryFlo web app or mobile app today. If that changes, this Policy and the App Store "privacy nutrition label" will be updated first.

4. Lawful basis (UK / EU GDPR Article 6)

Processing activityLawful basis
Providing the Service (account, inventory features)Performance of contract (Art 6(1)(b))
Billing and tax recordsLegal obligation (Art 6(1)(c)) and contract (Art 6(1)(b))
Security, abuse and fraud preventionLegitimate interests (Art 6(1)(f))
Responding to support requestsLegitimate interests (Art 6(1)(f)) / contract

5. How we use your data

  • To create and secure your account and organization
  • To operate the Service: sync inventory across devices, generate reports, send email notifications you've enabled (invites, purchase-order emails, account activation)
  • To bill you and comply with tax law, where you are on a paid plan
  • To detect and prevent abuse, fraud, and security incidents
  • To diagnose and fix errors (see Section 7 — error tracking)
  • To respond to support requests

6. Data storage and location

Customer data — the Postgres database and uploaded item photos — is hosted on a dedicated server operated on our behalf by OVH SAS in Roubaix, France (EU). We do not use a distributed cloud provider; there is one primary EU region.

7. Subprocessors and third parties

We share a limited amount of data with the following processors, only for the purpose listed:

ProcessorPurposeData sharedLocation
OVH SASServer hosting, database, backupsAll account and operational dataFrance (EU)
Backblaze Inc. (B2 storage)Offsite, GPG-encrypted copy of nightly backups (disaster recovery)Encrypted database and item-photo backups — unreadable without a private key we controlUSA — encrypted before leaving the EU server
Stripe Payments Europe LtdSubscription billing and payment processingBilling name/email, plan, payment method (we never see full card numbers)Ireland (EU), with global payment-network processing
Brevo SAS (or Resend, Inc.)Transactional email: account activation, team invitations, purchase-order emailsRecipient name/email and the email contentBrevo: France (EU). Resend: USA (used only if we switch providers)
Functional Software, Inc. (Sentry)Backend error tracking — disabled unless explicitly configured; only enabled in production to help us fix crashes quicklyStack traces and request metadata; we configure scrubbing of obvious secretsUSA — Standard Contractual Clauses

We do not sell personal data, and we do not use any advertising or cross-app tracking network.

8. International transfers

Where personal data is transferred outside the UK or European Economic Area (EEA) — for example, to Backblaze or Sentry, both US-based — we rely on the European Commission's Standard Contractual Clauses (2021/914), supplemented by the UK International Data Transfer Addendum where relevant.

9. Data retention

CategoryRetention period
Account data (name, email)Lifetime of your account, plus 30 days after deletion
Inventory and operational dataLifetime of your organization's subscription, plus a 30-day export window after cancellation
Billing records7 years, to meet UK tax-record obligations (Companies Act 2006, s.388)
Server logs (IP, request metadata)30 days
Encrypted offsite backupsRolling window — daily backups kept 14 days, monthly backups kept ~6 months, then deleted
Error reports (Sentry, when enabled)90 days

10. Your rights (UK / EU GDPR)

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and data (subject to legal retention obligations, e.g. billing records)
  • Object to or restrict certain processing
  • Receive an export of your organization's data (see Section 3 "Content you add") in a common format
  • Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority

To exercise any of these rights, email contact@inventoryflo.app. See also our Support page for the account-deletion and data-export process. We aim to respond within 30 days.

11. Cookies and local storage

The web app stores your sign-in session in your browser's local storage so you stay signed in; the mobile app stores it in the device's secure credential storage (iOS Keychain / Android Keystore). We do not use advertising cookies or third-party tracking pixels on the website or in the apps.

12. Security

  • Encryption in transit (TLS)
  • Passwords stored only as salted bcrypt hashes (never in plain text)
  • Role-based access control within your organization
  • Offsite backups are GPG-encrypted before they leave our server

If a personal-data breach affects your information, we will notify the ICO within 72 hours where required, and notify affected individuals without undue delay where there is a high risk to their rights and freedoms.

13. Children

The Service is a business tool intended for use by adults on behalf of a company or organization. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 (EU) or 13 (UK/US).

14. Changes to this Policy

We may update this Policy from time to time. When we do, we'll update the "Last updated" date above, and for material changes we'll notify account holders by email or in-app before the change takes effect.

15. Contact

MANARA DIGITAL LTD
Email: contact@inventoryflo.app

InventoryFlo
PrivacyTermsDPASupport© 2026 MANARA DIGITAL LTD