Privacy Policy

Last updated 27 July 2026

This policy explains what we collect when you use ERP MANAGEMENT, why we collect it, and the control you have over it. We've written it in plain English rather than legalese.

What we collect

There are two different kinds of data involved, and it matters which is which.

  • Account data — your name, email, company name and a securely hashed password. We need this to create your workspace and sign you in.
  • Workspace data — the business records you create or import: customers, invoices, products, employees and so on. This is your data. We store it so the product works; we don't mine it.
  • Basic technical data — standard server logs needed to operate and secure the service.

How we use it

Account data is used to authenticate you, provide the service, and contact you about your account. Workspace data is used only to render your workspace back to you and power features you invoke, such as search, reporting and automation.

We do not sell your data. We do not share your workspace data with third parties for advertising, and we don't use it to train anything.

Third parties that touch your data

The service runs on hosted infrastructure and a hosted database, which necessarily process the data you store in order to serve it back to you.

If you choose to connect an integration (for example Stripe or Shopify), you supply that provider's credentials and we call their API on your behalf to import the data you asked for. That is your choice and you can disconnect at any time.

Where your data lives and how long we keep it

Your workspace data is retained while your account is active. If a paid account lapses, the workspace is paused rather than deleted and the data remains available for 90 days so you can export or reactivate.

You can export every module to CSV at any time, and you can delete records — individually or in bulk — from within the product.

Security

Traffic is encrypted in transit. Passwords are hashed, never stored in readable form. Sessions use signed, httpOnly cookies. Workspace isolation is enforced on the server from your verified session, so one workspace cannot read another's data.

To be straight with you: we do not yet hold an independent security certification such as SOC 2, and we don't currently publish an at-rest encryption guarantee. Both are on the roadmap and we will say so clearly when they're real rather than implying them now.

Your rights

You can access and correct your data directly in the product, export it whenever you like, and ask us to delete your account and its data. Contact us and we'll action deletion requests.

Changes and contact

If this policy changes materially we'll update the date at the top and, for significant changes, notify account holders. Questions about privacy can be sent through the contact page.