Legal
Privacy
The short version: your stock data never reaches us, because there is no mechanism by which it could.
Last updated 11 September 2026 · Terms of sale
[LEGAL REVIEW — NOT YET DONE] This page was drafted by the person who built the product, not by a lawyer. It must be reviewed before the first paid sale, and this notice stays here until it has been. The data processing agreement, retention periods and breach procedure it refers to are written and are in the same state: real, and not yet reviewed.
The short version
SoftBo runs on a machine in your shop. What it knows — your products, your counts, your corrections — is a SQLite file on that machine. There is no pipe from it to us. Not one we choose not to use: one that does not exist.
That is the whole architecture, and everything below is a footnote to it.
Who we are
SoftBo is a trading name of Ion Borfotin — Podnik zahraničnej osoby, registered in the Slovak Republic, IČO 57 871 329. The full registration details, including our place of business, are on the terms of sale page.
For anything on this page, write to privacy@softbo.app.
What the app sends today
Nothing. There is no account system yet and no server to send anything to. The app does not phone home, does not report usage, and does not check in.
When enrolment ships, one thing changes: signing in once, at first run, to collect your licence. That sends your email address, your password and a machine fingerprint — and nothing about what you count, ever. After that the app confirms its licence about once a month. If it cannot, nothing changes.
What this website collects
No analytics, of any kind. No Google Analytics, no tag manager, no pixel, no cookie that follows you anywhere. There are no third-party requests on any page of this site. The fonts are served from here rather than from a font provider, precisely so that reading this page does not tell anybody else that you did.
Two things are recorded, and this is the complete list.
A log of pages that could not be found, so broken links can be fixed. It records the address asked for and the page you followed the link from. It does not record your IP address, a cookie, or any identifier of who you are.
Your IP address, briefly, as a rate limit. When you sign in or use the account pages, your address is used to count requests so that nobody can hammer the service. It is held in memory for that purpose only, it is never written to a log, never stored in the database, and never used to identify you. Our lawful basis is our legitimate interest in keeping the service standing up.
What we hold when you have an account
Not yet in force — there is no live account system. Written here so it is not a surprise later.
An account holds your email address, your name, your company name, your password (stored as a hash, never as text), the licences issued to you, and which machines those licences are installed on. That is the complete list. It holds nothing about your stock, because there is still no mechanism by which it could.
If you buy, we also hold what you bought, when, and for how much, together with the billing details an invoice needs. Card numbers never reach us — they go from you to Stripe, and we never see them.
Our lawful basis for all of this is that we need it to give you what you bought, and for the invoices, that the law requires us to keep them.
Connected systems
Not yet in force. If you later connect Xero, QuickBooks or Shopify through SoftBo, we hold the token that connection needs, encrypted, so your hub can ask for a short-lived key when it syncs.
What we store for a connection is the encrypted token, the identifier your provider uses for your shop or organisation, what permissions were granted, and the dates. We do not store anything from inside those systems — no invoices, no orders, no customers, no products. Your hub calls Xero, QuickBooks or Shopify directly with the short-lived key. Your data never travels through us.
Holding that token makes us a data processor, and business customers can ask us for a data processing agreement. Odoo, ERPNext and WooCommerce are different again: they use credentials you hold yourself, your hub talks to them directly, and nothing about them reaches us at all.
You can disconnect at any time. That deletes the token here and revokes it at the provider wherever the provider supports revocation.
How long we keep things
Your account: while it is active, and for twelve months after it lapses. We email you a month before it is deleted, so nothing disappears without warning. Signing in starts the clock again.
Connection tokens: until you disconnect or close your account, and then they are deleted and revoked.
Free trials that did not become purchases: six months.
Email you send us: three years.
The broken-link log: thirty days.
Invoices and accounting records: for as long as Slovak accounting law requires. This one is not ours to shorten, and closing your account does not remove it — an invoice is kept as the legal record of a sale and nothing more.
Who else sees it
A processor we cannot name is a processor we cannot be accountable for, so here is all of them. None of this is live yet, and the list is published in advance rather than after the fact.
netcup GmbH — the server everything runs on, in Austria. It holds everything we store, including encrypted connection tokens.
Stripe (Stripe Technology Europe Ltd, Ireland) — payments. It sees your name, email, billing address and what you bought. It never gives us your card number.
MailerSend (Lithuania) — sends your licence key, receipts and account email. It sees your email address and your name.
Google Workspace (Google Ireland Limited) — our mailbox, so it sees email you choose to send us. Google may process this in the United States under the EU–US Data Privacy Framework. Everything else above stays in the EU, and Google never sees a connection token.
There is no analytics provider, no content delivery network, and no error-reporting service. Their absence is deliberate.
We will give thirty days’ notice before adding or replacing any of these.
Your rights
Under the GDPR you can ask us to show you what we hold about you, correct it if it is wrong, delete it, give you a copy in a form you can take elsewhere, restrict what we do with it, or object to us using it. If we ever ask for your consent to something, you can withdraw it as easily as you gave it.
Write to privacy@softbo.app. We answer within one month. It is free, and we will not ask why.
The one thing we cannot delete on request is an invoice, because the law requires us to keep it.
If you think we have got something wrong, you can complain to the Slovak data protection authority — Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk. If you live elsewhere in the EU, you can complain to your own country’s authority instead. You do not have to talk to us first, though we would rather you did, because we can usually fix it faster.
Deleting your account
From your account page, under Close account. It does not go through us and you do not have to ask.
Closing an account removes it and everything attached to it, including any connection tokens, which are revoked at the provider as well as deleted here. Invoices remain, for the reason above.
Your stock data is unaffected, because we never had it. It is still the file on your machine, it still opens without us, and your licence still verifies without a network.
Getting in touch
Write to privacy@softbo.app. A real person reads it, because there is only one of us.
Our registered details and postal address are on the terms of sale page.
Changes to this policy
When the account system and the connection broker go live, the sections above marked “not yet in force” become live and this page is dated again.
If we change anything that materially affects you — a new sub-processor, a longer retention period, a new kind of data — we email everyone with an account before it takes effect, and we say what changed rather than telling you to re-read the page. Corrections to wording and typos we just fix, and the date at the top changes.