Privacy Policy
Last updated: 21 August 2026 · Effective: 21 August 2026
- Who we are
- Controller vs. Processor — our dual role
- Account data we collect (controller)
- Tenant business data (processor)
- Legal basis for processing
- Sub-processors
- Data retention
- Backup rules
- Log retention
- Cookies & tracking
- Marketing email, and how we measure it
- Your rights (Art. 15–21 GDPR)
- International transfers
- Security measures
- Breach notification
- Changes to this policy
- Contact & DPO
1. Who we are
Golden Inventory is a multi-tenant inventory management SaaS operated by Serhii Korsunenko (Golden Inventory, "we", "us", "our"), reachable at support@inventory-system.com. The service is hosted at inventory-system.com.
For GDPR purposes the lead supervisory authority is the Berlin Data Protection Authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit), as we are based in Berlin, Germany.
2. Controller vs. Processor — our dual role
We act in two distinct capacities under the GDPR:
- Controller (Art. 4(7)) for account data: user registration, authentication, IP addresses in access logs, Gumroad license-to-org mappings, and visitor analytics on our public landing pages. We determine the purposes and means of this processing ourselves.
- Processor (Art. 4(8)) for tenant business data: the parties (customers, vendors), documents, payments, stock movements, serial/lot numbers, vehicle/VIN data in the assets module, technician and waiter attribution records, Shopify/WooCommerce-imported customer records, webhook payloads, and document PDFs that you enter into your organization account. We process this data solely on your documented instructions as the controller of your own tenant data.
This policy covers both roles. Section 3 describes controller processing; section 4 describes processor processing. If you are a tenant (a business using Golden Inventory), you are the controller of your own business data and must have your own lawful basis for the personal data you enter — we provide an Art. 28 DPA template for this relationship.
3. Account data we collect (controller)
| Category | Examples | Purpose |
|---|---|---|
| Identity | Email address, full name (optional), Google account ID (if Google Sign-In used) | Account creation, authentication, password reset |
| Authentication | Hashed password, refresh token hashes, email verification tokens | Secure login, session management |
| Billing | Gumroad license key, subscription status, plan tier, payment amounts (no full card numbers — Gumroad is the merchant of record) | Plan enforcement, license linking |
| Usage metadata | IP address, User-Agent string, Referer header, visit timestamps | Security, abuse prevention, visitor analytics (landing pages only) |
| Support | Contact form submissions (name, email, company, message) | Customer support, sales inquiries |
We do not collect or process special categories of personal data (Art. 9 GDPR) as a controller. We do not make automated decisions with legal or similarly significant effects (Art. 22).
4. Tenant business data (processor)
When you use Golden Inventory as a business, you may enter personal data about your own customers, vendors, employees, and other parties. This data belongs to you — you are the controller. We process it on your behalf and on your documented instructions (the agreement you accept when creating an organization, supplemented by our Data Processing Agreement).
Personal data that may appear in tenant business data:
- Parties: customer/vendor/employee names, contact details (phone, email, address), tax IDs (VAT numbers)
- Documents: invoice/sales-order/purchase-order/estimate lines with party references, document PDFs with party names and addresses
- Payments: payment records linked to party accounts, terminal references
- Assets module: vehicle registration plates, VINs, meter readings linked to customer assets
- Labor lines: technician names on work orders and invoices
- Restaurant mode: waiter attribution on table tabs, server assignments
- E-commerce connectors: Shopify/WooCommerce-imported customer names, addresses, order history
- Webhook payloads: data you configure us to forward to your endpoints
Not in scope of personal data: item master data (SKUs, barcodes, descriptions), stock quantities, bill-of-material structures, and tax code definitions.
5. Legal basis for processing
As controller, we process account data on the following bases:
- Contract performance (Art. 6(1)(b)): account registration, authentication, plan enforcement, license verification, support responses.
- Legitimate interests (Art. 6(1)(f)): security logging (IP addresses), abuse prevention, aggregated visitor analytics on our landing pages, service improvement. You may object to legitimate-interest processing at any time (see section 11).
- Consent (Art. 6(1)(a)): Meta Pixel and Google Analytics on our public pages (optional, both gated behind the cookie consent banner — neither script is loaded until you accept). You may withdraw consent at any time via the cookie settings link in the page footer.
- Pre-contractual steps / legitimate interests (Art. 6(1)(b), 6(1)(f)): answering what you send us through the contact form on our landing page. Providing a name, an email address and a message is voluntary; without them we cannot reply.
- Legal obligation (Art. 6(1)(c)): retention of invoice data where required by commercial/tax law (e.g. §147 AO / GoBD in Germany — 10 years for invoices and booking records), cooperation with supervisory authorities.
As processor, we process tenant business data on the basis of your instructions (Art. 28(3)(a) GDPR) as documented in the DPA.
6. Sub-processors
We use the following sub-processors to deliver the service. Each has signed their own DPA with us (or we have accepted their standard DPA/AVV in their respective panels):
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Hetzner Online GmbH | VPS hosting (application server + database) | EU (Germany / Finland) | All account and tenant business data |
| Scaleway / OVH | Encrypted off-site backup storage (pgBackRest + restic) | EU (France) | Encrypted database backups (client-side AES-256-CBC) |
| nocdirect (Josef) | SMTP mail relay for transactional emails | US (TX) — EU SCCs in place via cPanel agreement | Email address, email content (verification, password reset, contact form) |
| Google Ireland Ltd. (Google Analytics 4) | Aggregated visitor statistics on public pages — only after consent | IE / US — EU SCCs + EU-US Data Privacy Framework | IP address (truncated by Google), device and browser data, pages viewed, cookie identifiers |
| Meta Platforms Ireland Ltd. (Meta Pixel) | Advertising attribution on public pages — only after consent | IE / US — EU SCCs + EU-US Data Privacy Framework | IP address, device and browser data, pages viewed, cookie identifiers |
| Gumroad, Inc. | Payment processing (Merchant of Record), subscription management, EU VAT handling | US — EU SCCs in place (Gumroad DPA) | Email, license key, subscription status, payment amounts |
Google and Meta are not sub-processors of tenant business data — they never receive it, and they are absent from the authenticated application. They are listed here because they receive visitor data from our public pages when, and only when, you consent. The DPA Annex, which governs tenant data, does not include them.
We will notify tenants of any new sub-processor at least 14 days before engagement, with the opportunity to object on reasonable data-protection grounds. The current list is also maintained in the DPA Annex.
7. Data retention
| Data category | Retention period | Basis |
|---|---|---|
| User account | Until deletion request or 2 years after last login | Contract + legitimate interest |
| Tenant business data | Until org deletion by tenant admin, or 30 days after subscription ends (grace period for export) | Processor — tenant instruction |
| Invoices & booking records | 10 years from end of calendar year (GoBD §147 AO for DE tenants) | Legal obligation — tenant's retention duty |
| Server access logs (with IPs) | 14 days (nginx), 30 days (application) | Security / abuse prevention |
| Backups | 30-day rolling retention (daily incrementals + weekly fulls) | Disaster recovery |
| Gumroad webhook events | Duration of subscription + 90 days | Billing audit trail |
| Contact form messages | 24 months in the support mailbox, then deleted | Answering and following up an inquiry |
8. Backup rules
To ensure service continuity, we maintain encrypted backups of the application database:
- Storage location: EU-owned and EU-located storage only (Hetzner Storage Box for primary backups, Scaleway/OVH object storage for secondary copies).
- Encryption: All backups are encrypted client-side (AES-256-CBC) before transmission. Storage providers cannot access plaintext data.
- Retention: 30-day rolling retention — daily incremental backups plus weekly full backups. Backups older than 30 days are automatically purged.
- Restore testing: A restore test is performed monthly to verify integrity and recoverability.
- Erasure requests and backups: When you request deletion of personal data, we erase it from the live database immediately. Because backups are encrypted at rest and retained for a maximum of 30 days, any residual copies age out automatically within that window. We do not perform surgical editing of backup archives; instead, we re-apply erasure instructions after any restore to ensure no deleted data re-enters the live system. This practice is stated transparently here so you can make an informed decision.
9. Log retention
- nginx access logs: Retained for 14 days, then auto-rotated (logrotate, daily rotation, 14 keep). IP addresses in access logs are truncated after rotation.
- Application logs: Retained for 30 days (RotatingFileHandler, 10 MB × 5 files). Application logs may contain IP addresses for error diagnosis and abuse prevention.
- Database visitor log (
visitor_logtable): IP + User-Agent retained for 90 days for aggregated analytics, then purged by a nightly cron job.
10. Cookies & tracking
The Golden Inventory application itself is cookieless. We use no analytics, no tracking pixels, and no third-party scripts inside the authenticated app — your business data stays between you and the server.
On our public landing pages only:
- Essential (always on): a session-localStorage key (
gi_lang) to remember your language preference; a consent cookie (gi_consent) to remember your tracking preferences. Neither contains personal data nor is sent to any server. - Optional — Meta Pixel: with your consent, we load a Meta (Facebook) conversion pixel for ad attribution. It sets third-party cookies.
- Optional — Google Analytics 4: with your consent, we load Google Analytics for aggregated visitor statistics (which pages are read, from which country, on which device). It sets third-party cookies.
Neither script exists on the page until you accept. Both are loaded by one
file (/static/analytics.js), which starts nothing unless the consent you stored
says so. Choosing "Essential only", or simply not answering the banner, means no analytics
request leaves your browser at all. Consent is collected by a banner on first visit, stored in
localStorage as gi_consent, and can be changed at any time through
the "Cookie settings" link in the page footer.
The contact form on our landing page sends only what you type into it — your name, email address, optional company and your message — to our own server, which forwards it by email to our support address. The anti-spam question is arithmetic computed on our own server: there is no reCAPTCHA or comparable third-party widget anywhere on our pages. Your IP address is used to rate-limit submissions and is not stored with the message.
What you write to us is never passed to Google or Meta. The message goes to our own server and from there to our support mailbox, and nowhere else. The Meta Pixel is initialised without advanced matching, so no email address — hashed or otherwise — is handed to it, and we operate no server-side Conversions API. The two tags see that a page was viewed; they do not see what you typed on it.
11. Marketing email, and how we measure it
We keep a small customer-relationship database of our own: the people who bought our earlier products, the people who wrote to us, and the people who ticked the marketing box when they registered or subscribed to our letter. It holds a name, an email address, a company, a country, a language, and what the person asked us for. It is separate from tenant business data, and no tenant's records are ever used for our own marketing.
Legal basis. A letter goes out on one of three bases, and the basis is stored on each record: your consent (Art. 6(1)(a) GDPR, and §7 Abs. 2 Nr. 2 UWG), our legitimate interest in writing to an existing business customer about a similar product (Art. 6(1)(f), and §7 Abs. 3 UWG), or a business-to-business contact where that interest applies. For recipients in Germany we write on consent only.
The checkbox is never pre-ticked, and the exact sentence you agreed to is stored with the date, the language and the version, so that we can show later what you read. A newsletter subscription needs a second click in a confirmation email before anything else is sent (double opt-in).
What we measure in an email. Our letters contain a 1×1 image that reports that the message was opened, and the links in them pass through our own server so that a click can be counted. We do this to learn which letters are worth writing, and the numbers are only ever aggregated by us. No email service provider, advertising network or analytics company receives this data. An open number is an upper bound: a mail client that pre-loads images reports an open with no person behind it.
How to stop it. Every letter carries an unsubscribe link and the
List-Unsubscribe header your mail client uses for its own unsubscribe button. One
click stops every letter; the preference page lets you keep some kinds and drop the rest. You
can also ask us not to measure your letters at all, and we will send them with no image and
with plain links. Write to
feedback@inventory-system.com.
Advertisements. Where we run advertisements or publish posts on Google, LinkedIn, X, Instagram or Facebook, we read our own campaign numbers — impressions, clicks and cost — from those networks and count the registrations that arrived through our own links. We do not upload customer lists, email addresses or hashes of email addresses to any advertising platform, and we operate no server-side conversion interface.
Retention. A marketing record is kept while the relationship lasts and is removed on request. An address that unsubscribed is kept on a suppression list — the address and nothing else — because that is the only way to be sure it is never written to again.
12. Your rights (Art. 15–21 GDPR)
As a data subject, you have the following rights regarding your account data (controller processing):
- Access (Art. 15): request a copy of your personal data.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your data ("right to be forgotten"), subject to legal retention obligations (e.g. invoices under GoBD §147). Where erasure is restricted by law, we restrict processing instead (Art. 18). For tenant business data, party anonymization is used instead of hard-deletion where invoices are under legal retention: we overwrite name/contact fields with placeholders while preserving document numbers and amounts for tax audit purposes.
- Restriction (Art. 18): request restricted processing while a dispute is pending.
- Portability (Art. 20): receive your data in a structured, machine-readable format (JSON/XLSX).
- Objection (Art. 21): object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds.
- Withdraw consent (Art. 7(3)): withdraw cookie/tracking consent at any time via the "Cookie settings" link in the footer. Withdrawal does not affect the lawfulness of processing before withdrawal.
For tenant business data, direct your requests to the tenant (your service provider) who is the controller. We assist tenants in fulfilling data subject requests as required by Art. 28(3)(e) GDPR — see the DPA for the procedure.
To exercise any of these rights, email us at support@inventory-system.com. We respond within 30 days (Art. 12(3)). Verification of identity may be required. You also have the right to lodge a complaint with your local supervisory authority.
13. International transfers
All primary processing (application server, database, primary backups) happens on servers in the European Union (Germany / Finland via Hetzner; France via Scaleway/OVH). Two sub-processors operate outside the EU:
- nocdirect (US): SMTP relay for transactional email. EU Standard Contractual Clauses are in place via the hosting provider's data processing terms.
- Gumroad (US): payment processing and subscription management. Gumroad's DPA includes EU Standard Contractual Clauses. Only email, license key, and payment metadata are shared — no tenant business data.
- Google and Meta (IE / US): analytics and advertising attribution on our public pages, only if you accept them in the cookie banner. Both are contracted through their Irish entities, rely on EU Standard Contractual Clauses and are certified under the EU-US Data Privacy Framework. Neither receives anything if you do not consent, and neither is present anywhere inside the authenticated application.
We do not transfer tenant business data (documents, parties, stock) outside the EU.
14. Security measures
- All traffic encrypted in transit (TLS 1.3, HSTS).
- Passwords hashed with bcrypt; refresh tokens hashed with SHA-256 at rest.
- Database access restricted to the application via internal Docker network (no public port).
- Rate limiting on authentication endpoints (SlowAPI).
- Immutable audit log for billing webhook events.
- Org-scoped data isolation: every tenant query is filtered by
org_idat the database level; cross-tenant data access is architecturally prevented (no shared tenant-data tables). - Nightly database backups, encrypted client-side, stored in EU locations.
- Monthly restore tests.
- Admin access restricted to verified admin email addresses via JWT.
15. Breach notification
In the event of a personal data breach, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware (Art. 33 GDPR), where the breach is likely to result in a risk to individuals' rights and freedoms.
- Notify affected data subjects without undue delay (Art. 34) where the breach is likely to result in a high risk.
- Notify affected tenants (as our controllers) without undue delay so they can meet their own Art. 33/34 obligations.
16. Changes to this policy
We will post changes on this page and, for material changes affecting account data, notify account holders by email at least 14 days in advance. Continued use after the effective date constitutes acceptance. For material changes affecting processor obligations, we follow the DPA amendment procedure.
17. Contact & supervisory authority
Data Protection Officer (not required by law for our size, but designated voluntarily):
Serhii Korsunenko
support@inventory-system.com
Berlin, Germany
You have the right to lodge a complaint with a supervisory authority. The lead authority for
Golden Inventory is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
www.datenschutz-berlin.de