Privacy
Transparent, understandable and without data trading
Effective 14 August 2026. This policy describes SmartDepot's data processing.
SmartDepot is a tool, not a data trade. We do not sell personal data or create advertising profiles.
Controller
Alf Müller InformatikDorfstrasse 2
4556 Steinhof SO
Switzerland
support@smartdepot.org
Data we process
- Website and server access, IP address, time, target and technical errors;
- contact forms, support and privacy requests;
- account, login, profile, workspace and role information;
- locations, items, quantities, movements, projects and receiving;
- QR/barcode actions and temporary vision images and results;
- merchant carts, orders, shipments, OAuth grants and connected apps;
- subscription, invoice, payment status, security and audit records.
Why we use data
To provide and secure SmartDepot, fulfil requested functions, provide support, bill services, prevent abuse, diagnose faults and comply with legal obligations. We do not sell this data or use it for third-party advertising profiles.
Merchants and developer apps
Data can come directly from you or an authorized merchant. The merchant remains responsible for its collection. SmartDepot uses submitted cart, order and shipment data for import, receiving and put-away. API v1 gives merchants no read access to users, products, locations or inventory. Grants are visible and revocable.
Shop Import browser extension
The extension reads AliExpress data only after you click “Collect orders”. It processes the order number and date, merchant, selected products and variants, quantities, prices, currency, product links and images, and shipment, parcel and tracking details. This data remains in local extension storage until you review it. Only selected items are sent over an encrypted connection to your paired SmartDepot workspace to process orders, incoming goods, projects and product names. Cookies, session tokens, recipient names, delivery addresses, email addresses and phone numbers are never stored or transferred to SmartDepot. Complete order data is removed locally after a successful import; minimal import identifiers and hashes prevent duplicate imports. Drafts for failed or not-yet-imported orders remain local until you import or complete them, revoke the connection, or clear the extension data. For AI naming suggestions that you explicitly request for new items, SmartDepot sends only product identifiers, title, variant and active language to the configured AI provider. Extension connections are visible and revocable in SmartDepot at any time. We use extension data only to provide and improve the visible Shop Import feature, and not for advertising, credit decisions or data sales unrelated to the user-facing purpose.
Vision
Images are validated, re-encoded and used only for the requested recognition. Temporary files are deleted within 15 minutes and results removed from detection sessions after 90 days. Suggestions become inventory data only after confirmation.
Stripe payments
SmartDepot uses Stripe as the payment processor for paid services. Billing/contact information, amount, currency, customer and subscription references, method and status can be sent to Stripe. Full card or wallet details are collected in Stripe Checkout and not stored by SmartDepot. Stripe may process data abroad for payment and fraud prevention. See the Stripe Privacy Center.
Merchant recommendations and affiliate links
If SmartDepot recommends a merchant for restocking through an affiliate link, the link is clearly labelled. The merchant's or affiliate network's privacy terms apply when it is opened. SmartDepot does not return inventory, storage locations or user profiles to merchants through API v1.
Recipients and international transfers
Data is shared only with necessary hosting, email, payment, security or integration providers. Recipient countries and safeguards are documented before use. Processors may act only on instructions and for the agreed purpose.
Retention
- vision images: at most 15 minutes;
- vision results: 90 days;
- API audit events: 365 days;
- completed privacy requests: 3 years;
- raw payment data: 10 years, then redacted;
- operational logs and encrypted backups: 30 days each;
- contact requests: normally 12 months;
- inventory, accounting and journal records: until a later lawful deletion approval.
Cookies and tracking
SmartDepot uses only first-party storage required for the requested app function:
_smartdepot_key: signed session cookie for the session, login security and LiveView navigation; normally deleted when the browser closes;_smart_depot_web_user_remember_me: signed optional login cookie, set only when “remember me” is selected and expiring after 14 days;smartdepot:theme: local browser storage for the selected light or dark appearance, retained until changed or browser data is cleared.
The marketing site currently has no advertising or analytics tracking, so it does not display a decorative cookie banner.
Your rights
You may request access, correction, export or deletion and object to processing that is not required. Account data and inventory can be exported in the app, and account deletion can be requested in settings. Contact support@smartdepot.org.