Privacy Policy
Last updated July 3, 2026
On this page
Pallet is an inventory tracking service operated by InnoByte OÜ, registry code 17288940, Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond, 15551, Estonia. This Privacy Policy explains what information we collect, how we use it, which service providers help us run Pallet, and the choices and rights you have. It applies to palletstore.xyz, the Pallet web application, account sign-in, support communications, billing, integrations, and related product features.
Who is responsible for your data
InnoByte OÜ is the data controller for personal information processed for Pallet, unless this policy says otherwise. If your business uses Pallet to store inventory records, team-member details, customer references, supplier information, photos, or other business content, your business decides what to put into Pallet. In that case, Pallet acts as a service provider for that workspace content.
You can contact us about privacy at info@innobytes.io.
Information we collect
We collect account information such as your name, email address, login provider, profile details, avatar, phone number, job title, workspace membership, role, and account settings. If you sign in with Google, Google provides basic account information needed to create and secure your Pallet session.
We collect workspace and inventory content that you or your team add to Pallet. This may include workspace names, team invites, folders, item names, SKUs, quantities, thresholds, costs, sale prices, profit and stock movement history, suppliers, storage locations, item photos, custom fields, QR label data, activity history, and notes or prompts you enter into the app.
If you use optional integrations, we collect the information needed to connect and operate them. For Telegram, this can include Telegram chat IDs, user IDs, usernames, first and last names, chat titles, pairing codes, bot settings, messages or commands sent to the bot, and pending bot actions. For Shopify, this can include your shop domain, shop name, connection status, access token, product and variant identifiers, inventory item identifiers, sync settings, webhook events, and imported product data. For AI and voice features, this can include prompts, uploaded files, item photos, voice recordings or transcripts, generated drafts, assistant responses, usage events, and usage limits.
We collect payment and subscription information through Stripe, including customer and subscription identifiers, plan, price, billing status, renewal period, invoices, checkout and customer portal events, and related billing metadata. Pallet does not store full card numbers. Payment card handling is provided by Stripe.
We collect technical and usage information such as page views, browser and device details, approximate location derived from IP address, referring pages, session events, error and security logs, authentication events, support chat messages, and timestamps. We use Google Analytics to understand website and product usage, Google Search Console to understand how our public website appears in Google Search, and Crisp to provide website chat support when enabled.
How we use information
We use information to provide and operate Pallet, including to:
- create accounts, authenticate users, and keep sessions secure;
- create and manage workspaces, team access, folders, inventory items, stock history, QR labels, and settings;
- store and display photos, attachments, activity history, low-stock alerts, and reports;
- process subscriptions, plan limits, invoices, trials, upgrades, downgrades, and cancellations;
- send transactional emails such as confirmations, password resets, workspace invites, and important service messages;
- operate optional AI, voice, Telegram, and Shopify features when you enable them;
- monitor reliability, prevent abuse, investigate errors, protect accounts, and enforce our terms;
- measure website and product performance, improve Pallet, and understand which pages and features are useful;
- comply with legal, tax, accounting, security, and regulatory obligations.
Legal bases
If the GDPR or similar laws apply, we rely on these legal bases: performance of a contract to provide Pallet and manage your account; legitimate interests to secure, improve, and operate the service; consent where required for optional cookies, marketing, or specific integrations; and legal obligations for tax, accounting, billing, fraud prevention, and compliance.
Service providers
We use trusted providers to run Pallet. They process information only as needed to provide their services to us, subject to their own security and privacy commitments.
- Supabase provides authentication, database, authorization, storage-related infrastructure, and Edge Functions.
- Google provides Google sign-in, Google Analytics, Google Search Console, and related security services.
- Stripe provides checkout, subscription billing, invoices, payment processing, and billing portal services.
- Cloudflare R2 stores item photos and public media assets when those features are used.
- Resend helps deliver transactional emails such as workspace invites and account emails.
- Crisp provides website chat support and related support inbox tools.
- Telegram provides the messaging platform used by the optional Pallet bot.
- Shopify provides store connection, product import, inventory sync, and webhook delivery when you connect a Shopify store.
- OpenAI may process prompts, files, and responses when you connect ChatGPT for Copilot-supported requests.
- Hosting, deployment, logging, DNS, and security providers may process technical data needed to make Pallet available and reliable.
Security
We use technical and organizational measures designed to protect information, including authenticated access, role-based workspace access, database row-level security, encrypted transport, provider access controls, and separation between client-side and server-side secrets. No service can guarantee perfect security, so you should use a strong password, protect your Google account, and limit team access to people who need it.
International transfers
Pallet is operated from Estonia and uses service providers that may process information in the European Economic Area, the United States, and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses, provider data processing terms, and other lawful transfer mechanisms.
Data retention
We keep account and workspace data while your account or workspace is active, and for a reasonable period after deletion where needed for backup recovery, legal compliance, dispute resolution, fraud prevention, accounting, or security. Inventory records, photos, stock history, activity history, integrations, and team data are generally kept until you delete them, close the workspace, or request deletion where applicable.
Billing records may be kept for the period required by tax and accounting laws. Security logs, analytics records, temporary pairing codes, webhook events, and AI usage events may be kept for shorter or longer periods depending on operational, security, and legal needs.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to the processing of your personal information. You may also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with a data protection authority.
You can update many details directly in Pallet, disconnect integrations, remove team members, delete inventory content, or contact us for help. We may need to verify your identity before acting on a request. If your data is controlled by a business workspace rather than directly by Pallet, we may refer your request to that workspace owner.
Children
Pallet is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to Pallet, contact us so we can review and delete it where appropriate.
Changes to this policy
We may update this Privacy Policy as Pallet changes or as legal, technical, or business requirements evolve. When we make material changes, we will update the date above and may notify users through the app, by email, or by another reasonable method.
Contact
For privacy questions or requests, contact InnoByte OÜ at info@innobytes.io. Please include enough detail for us to understand your request and locate the relevant account or workspace.