Skip to main content

Privacy policy

Last updated: 23 August 2026

Not yet reviewed by a lawyer. Everything below is an accurate description of how Infinity Nexa handles data. It has not been checked against the data-protection law of any particular country, and the governing-law and contact details still need to be filled in. Have it reviewed before taking paying customers.

Who controls what

You are the controller of the business records you put into your workspace — your products, stock, customers, suppliers and documents. We are a processor acting on your instructions for those. We are the controller of your own account details and of the operational logs we keep to run and secure the service.

What we store

  • Account details. Name, email address, optional phone number and avatar, and a hashed password. We never see your password in the clear.
  • Workspace records. Everything you enter: products, prices and costs, stock levels and movements, warehouses, suppliers, customers, purchase orders, sales, invoices, payments and expenses.
  • Audit trail. Who changed what and when inside your workspace. This is append-only by design — it cannot be edited or selectively removed, because a tamperable audit trail is not an audit trail.
  • Operational logs. Errors and request diagnostics. Configured to exclude request bodies, headers and cookies, so your business records do not appear in them.

We do not use tracking or advertising cookies. The only cookie set is the one that keeps you signed in.

Who else processes it

These are the only third parties involved, and what each one sees:

  • Supabase — database, authentication and file storage. Holds all workspace records and account details.
  • Vercel — application hosting. Processes requests in transit; stores no records itself.
  • Resend — sends invitation emails. Sees the recipient address, the workspace name and the role they were invited as.
  • Sentry — error monitoring, when enabled. Sees error messages and stack traces, with request contents stripped.
  • Stripe — payment processing, once billing is live. Sees your billing details; card numbers reach Stripe directly and never touch our servers.

How your workspace is kept separate

Separation is enforced by the database itself, not by application code that could forget. Every record carries the workspace it belongs to, and row-level security policies mean a query for another workspace’s data returns nothing — including for us. This is verified by an automated test suite on every change.

Getting your data back

Settings → General → Export your data downloads everything in your workspace as a single JSON file, at any time, without asking us. Individual reports and lists also export to CSV and Excel.

Deletion and retention

Records you delete inside the app are marked deleted and retained, so that historical documents still show what they referred to at the time — a deleted product must not blank out last year’s invoices.

Deleting your workspace removes all of its records, including the audit trail. Ask us and we will do it; it is not reversible, and no backup copy is kept beyond the retention window below.

Backups are held by Supabase according to the plan in use and are overwritten on that schedule. A deletion request is reflected in backups as they roll over rather than immediately.

Your rights

You can access, correct, export and erase your data. Access, correction and export are available in the app without contacting anyone. For erasure, or if you are unhappy with how we have handled something, contact us at the address below.

Contact

[add your contact address and registered entity]

Terms of service