Privacy Policy

Last updated: 21 August 2026 · Effective: 21 August 2026

1. Who we are

Golden Inventory is a multi-tenant inventory management SaaS operated by Serhii Korsunenko (Golden Inventory, "we", "us", "our"), reachable at support@inventory-system.com. The service is hosted at inventory-system.com.

For GDPR purposes the lead supervisory authority is the Berlin Data Protection Authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit), as we are based in Berlin, Germany.

2. Controller vs. Processor — our dual role

We act in two distinct capacities under the GDPR:

This policy covers both roles. Section 3 describes controller processing; section 4 describes processor processing. If you are a tenant (a business using Golden Inventory), you are the controller of your own business data and must have your own lawful basis for the personal data you enter — we provide an Art. 28 DPA template for this relationship.

3. Account data we collect (controller)

CategoryExamplesPurpose
IdentityEmail address, full name (optional), Google account ID (if Google Sign-In used)Account creation, authentication, password reset
AuthenticationHashed password, refresh token hashes, email verification tokensSecure login, session management
BillingGumroad license key, subscription status, plan tier, payment amounts (no full card numbers — Gumroad is the merchant of record)Plan enforcement, license linking
Usage metadataIP address, User-Agent string, Referer header, visit timestampsSecurity, abuse prevention, visitor analytics (landing pages only)
SupportContact form submissions (name, email, company, message)Customer support, sales inquiries

We do not collect or process special categories of personal data (Art. 9 GDPR) as a controller. We do not make automated decisions with legal or similarly significant effects (Art. 22).

4. Tenant business data (processor)

When you use Golden Inventory as a business, you may enter personal data about your own customers, vendors, employees, and other parties. This data belongs to you — you are the controller. We process it on your behalf and on your documented instructions (the agreement you accept when creating an organization, supplemented by our Data Processing Agreement).

Personal data that may appear in tenant business data:

Not in scope of personal data: item master data (SKUs, barcodes, descriptions), stock quantities, bill-of-material structures, and tax code definitions.

As controller, we process account data on the following bases:

As processor, we process tenant business data on the basis of your instructions (Art. 28(3)(a) GDPR) as documented in the DPA.

6. Sub-processors

We use the following sub-processors to deliver the service. Each has signed their own DPA with us (or we have accepted their standard DPA/AVV in their respective panels):

Sub-processorPurposeLocationData processed
Hetzner Online GmbH VPS hosting (application server + database) EU (Germany / Finland) All account and tenant business data
Scaleway / OVH Encrypted off-site backup storage (pgBackRest + restic) EU (France) Encrypted database backups (client-side AES-256-CBC)
nocdirect (Josef) SMTP mail relay for transactional emails US (TX) — EU SCCs in place via cPanel agreement Email address, email content (verification, password reset, contact form)
Google Ireland Ltd. (Google Analytics 4) Aggregated visitor statistics on public pages — only after consent IE / US — EU SCCs + EU-US Data Privacy Framework IP address (truncated by Google), device and browser data, pages viewed, cookie identifiers
Meta Platforms Ireland Ltd. (Meta Pixel) Advertising attribution on public pages — only after consent IE / US — EU SCCs + EU-US Data Privacy Framework IP address, device and browser data, pages viewed, cookie identifiers
Gumroad, Inc. Payment processing (Merchant of Record), subscription management, EU VAT handling US — EU SCCs in place (Gumroad DPA) Email, license key, subscription status, payment amounts

Google and Meta are not sub-processors of tenant business data — they never receive it, and they are absent from the authenticated application. They are listed here because they receive visitor data from our public pages when, and only when, you consent. The DPA Annex, which governs tenant data, does not include them.

We will notify tenants of any new sub-processor at least 14 days before engagement, with the opportunity to object on reasonable data-protection grounds. The current list is also maintained in the DPA Annex.

7. Data retention

Data categoryRetention periodBasis
User accountUntil deletion request or 2 years after last loginContract + legitimate interest
Tenant business dataUntil org deletion by tenant admin, or 30 days after subscription ends (grace period for export)Processor — tenant instruction
Invoices & booking records10 years from end of calendar year (GoBD §147 AO for DE tenants)Legal obligation — tenant's retention duty
Server access logs (with IPs)14 days (nginx), 30 days (application)Security / abuse prevention
Backups30-day rolling retention (daily incrementals + weekly fulls)Disaster recovery
Gumroad webhook eventsDuration of subscription + 90 daysBilling audit trail
Contact form messages24 months in the support mailbox, then deletedAnswering and following up an inquiry

8. Backup rules

To ensure service continuity, we maintain encrypted backups of the application database:

9. Log retention

10. Cookies & tracking

The Golden Inventory application itself is cookieless. We use no analytics, no tracking pixels, and no third-party scripts inside the authenticated app — your business data stays between you and the server.

On our public landing pages only:

Neither script exists on the page until you accept. Both are loaded by one file (/static/analytics.js), which starts nothing unless the consent you stored says so. Choosing "Essential only", or simply not answering the banner, means no analytics request leaves your browser at all. Consent is collected by a banner on first visit, stored in localStorage as gi_consent, and can be changed at any time through the "Cookie settings" link in the page footer.

The contact form on our landing page sends only what you type into it — your name, email address, optional company and your message — to our own server, which forwards it by email to our support address. The anti-spam question is arithmetic computed on our own server: there is no reCAPTCHA or comparable third-party widget anywhere on our pages. Your IP address is used to rate-limit submissions and is not stored with the message.

What you write to us is never passed to Google or Meta. The message goes to our own server and from there to our support mailbox, and nowhere else. The Meta Pixel is initialised without advanced matching, so no email address — hashed or otherwise — is handed to it, and we operate no server-side Conversions API. The two tags see that a page was viewed; they do not see what you typed on it.

11. Marketing email, and how we measure it

We keep a small customer-relationship database of our own: the people who bought our earlier products, the people who wrote to us, and the people who ticked the marketing box when they registered or subscribed to our letter. It holds a name, an email address, a company, a country, a language, and what the person asked us for. It is separate from tenant business data, and no tenant's records are ever used for our own marketing.

Legal basis. A letter goes out on one of three bases, and the basis is stored on each record: your consent (Art. 6(1)(a) GDPR, and §7 Abs. 2 Nr. 2 UWG), our legitimate interest in writing to an existing business customer about a similar product (Art. 6(1)(f), and §7 Abs. 3 UWG), or a business-to-business contact where that interest applies. For recipients in Germany we write on consent only.

The checkbox is never pre-ticked, and the exact sentence you agreed to is stored with the date, the language and the version, so that we can show later what you read. A newsletter subscription needs a second click in a confirmation email before anything else is sent (double opt-in).

What we measure in an email. Our letters contain a 1×1 image that reports that the message was opened, and the links in them pass through our own server so that a click can be counted. We do this to learn which letters are worth writing, and the numbers are only ever aggregated by us. No email service provider, advertising network or analytics company receives this data. An open number is an upper bound: a mail client that pre-loads images reports an open with no person behind it.

How to stop it. Every letter carries an unsubscribe link and the List-Unsubscribe header your mail client uses for its own unsubscribe button. One click stops every letter; the preference page lets you keep some kinds and drop the rest. You can also ask us not to measure your letters at all, and we will send them with no image and with plain links. Write to feedback@inventory-system.com.

Advertisements. Where we run advertisements or publish posts on Google, LinkedIn, X, Instagram or Facebook, we read our own campaign numbers — impressions, clicks and cost — from those networks and count the registrations that arrived through our own links. We do not upload customer lists, email addresses or hashes of email addresses to any advertising platform, and we operate no server-side conversion interface.

Retention. A marketing record is kept while the relationship lasts and is removed on request. An address that unsubscribed is kept on a suppression list — the address and nothing else — because that is the only way to be sure it is never written to again.

12. Your rights (Art. 15–21 GDPR)

As a data subject, you have the following rights regarding your account data (controller processing):

For tenant business data, direct your requests to the tenant (your service provider) who is the controller. We assist tenants in fulfilling data subject requests as required by Art. 28(3)(e) GDPR — see the DPA for the procedure.

To exercise any of these rights, email us at support@inventory-system.com. We respond within 30 days (Art. 12(3)). Verification of identity may be required. You also have the right to lodge a complaint with your local supervisory authority.

13. International transfers

All primary processing (application server, database, primary backups) happens on servers in the European Union (Germany / Finland via Hetzner; France via Scaleway/OVH). Two sub-processors operate outside the EU:

We do not transfer tenant business data (documents, parties, stock) outside the EU.

14. Security measures

15. Breach notification

In the event of a personal data breach, we will:

16. Changes to this policy

We will post changes on this page and, for material changes affecting account data, notify account holders by email at least 14 days in advance. Continued use after the effective date constitutes acceptance. For material changes affecting processor obligations, we follow the DPA amendment procedure.

17. Contact & supervisory authority

Data Protection Officer (not required by law for our size, but designated voluntarily):
Serhii Korsunenko
support@inventory-system.com
Berlin, Germany

You have the right to lodge a complaint with a supervisory authority. The lead authority for Golden Inventory is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
www.datenschutz-berlin.de