Privacy Policy

Last updated July 3, 2026

On this page

Pallet is an inventory tracking service operated by InnoByte OÜ, registry code 17288940, Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond, 15551, Estonia. This Privacy Policy explains what information we collect, how we use it, which service providers help us run Pallet, and the choices and rights you have. It applies to palletstore.xyz, the Pallet web application, account sign-in, support communications, billing, integrations, and related product features.

Who is responsible for your data

InnoByte OÜ is the data controller for personal information processed for Pallet, unless this policy says otherwise. If your business uses Pallet to store inventory records, team-member details, customer references, supplier information, photos, or other business content, your business decides what to put into Pallet. In that case, Pallet acts as a service provider for that workspace content.

You can contact us about privacy at info@innobytes.io.

Information we collect

We collect account information such as your name, email address, login provider, profile details, avatar, phone number, job title, workspace membership, role, and account settings. If you sign in with Google, Google provides basic account information needed to create and secure your Pallet session.

We collect workspace and inventory content that you or your team add to Pallet. This may include workspace names, team invites, folders, item names, SKUs, quantities, thresholds, costs, sale prices, profit and stock movement history, suppliers, storage locations, item photos, custom fields, QR label data, activity history, and notes or prompts you enter into the app.

If you use optional integrations, we collect the information needed to connect and operate them. For Telegram, this can include Telegram chat IDs, user IDs, usernames, first and last names, chat titles, pairing codes, bot settings, messages or commands sent to the bot, and pending bot actions. For Shopify, this can include your shop domain, shop name, connection status, access token, product and variant identifiers, inventory item identifiers, sync settings, webhook events, and imported product data. For AI and voice features, this can include prompts, uploaded files, item photos, voice recordings or transcripts, generated drafts, assistant responses, usage events, and usage limits.

We collect payment and subscription information through Stripe, including customer and subscription identifiers, plan, price, billing status, renewal period, invoices, checkout and customer portal events, and related billing metadata. Pallet does not store full card numbers. Payment card handling is provided by Stripe.

We collect technical and usage information such as page views, browser and device details, approximate location derived from IP address, referring pages, session events, error and security logs, authentication events, support chat messages, and timestamps. We use Google Analytics to understand website and product usage, Google Search Console to understand how our public website appears in Google Search, and Crisp to provide website chat support when enabled.

How we use information

We use information to provide and operate Pallet, including to:

  • create accounts, authenticate users, and keep sessions secure;
  • create and manage workspaces, team access, folders, inventory items, stock history, QR labels, and settings;
  • store and display photos, attachments, activity history, low-stock alerts, and reports;
  • process subscriptions, plan limits, invoices, trials, upgrades, downgrades, and cancellations;
  • send transactional emails such as confirmations, password resets, workspace invites, and important service messages;
  • operate optional AI, voice, Telegram, and Shopify features when you enable them;
  • monitor reliability, prevent abuse, investigate errors, protect accounts, and enforce our terms;
  • measure website and product performance, improve Pallet, and understand which pages and features are useful;
  • comply with legal, tax, accounting, security, and regulatory obligations.

Service providers

We use trusted providers to run Pallet. They process information only as needed to provide their services to us, subject to their own security and privacy commitments.

  • Supabase provides authentication, database, authorization, storage-related infrastructure, and Edge Functions.
  • Google provides Google sign-in, Google Analytics, Google Search Console, and related security services.
  • Stripe provides checkout, subscription billing, invoices, payment processing, and billing portal services.
  • Cloudflare R2 stores item photos and public media assets when those features are used.
  • Resend helps deliver transactional emails such as workspace invites and account emails.
  • Crisp provides website chat support and related support inbox tools.
  • Telegram provides the messaging platform used by the optional Pallet bot.
  • Shopify provides store connection, product import, inventory sync, and webhook delivery when you connect a Shopify store.
  • OpenAI may process prompts, files, and responses when you connect ChatGPT for Copilot-supported requests.
  • Hosting, deployment, logging, DNS, and security providers may process technical data needed to make Pallet available and reliable.

Sharing

We do not sell your personal information. We share information only when needed to operate Pallet, when you direct us to connect an integration, when your workspace settings allow team members to access shared content, when required by law, or when necessary to protect Pallet, our users, and the public.

If you invite team members, they may see workspace content according to their role. If you connect Telegram or Shopify, information may flow between Pallet and those services so the integration can work. If you use AI features, relevant prompts, files, inventory context, and generated responses may be sent to the configured AI provider to complete your request.

Cookies and analytics

Pallet uses essential browser storage and cookies for sign-in, session security, workspace preferences, and core app functionality. Without these, the app may not work correctly. We also use Google Analytics to measure page views and usage patterns. Analytics helps us understand traffic, improve the product, and diagnose issues.

Google Search Console is used for public website performance in Google Search. It provides aggregated search and indexing information; it is not used to read your private inventory data.

You can control cookies through your browser settings. Blocking some storage may prevent login, checkout, or app features from working.

Security

We use technical and organizational measures designed to protect information, including authenticated access, role-based workspace access, database row-level security, encrypted transport, provider access controls, and separation between client-side and server-side secrets. No service can guarantee perfect security, so you should use a strong password, protect your Google account, and limit team access to people who need it.

International transfers

Pallet is operated from Estonia and uses service providers that may process information in the European Economic Area, the United States, and other countries. Where required, we rely on appropriate safeguards such as standard contractual clauses, provider data processing terms, and other lawful transfer mechanisms.

Data retention

We keep account and workspace data while your account or workspace is active, and for a reasonable period after deletion where needed for backup recovery, legal compliance, dispute resolution, fraud prevention, accounting, or security. Inventory records, photos, stock history, activity history, integrations, and team data are generally kept until you delete them, close the workspace, or request deletion where applicable.

Billing records may be kept for the period required by tax and accounting laws. Security logs, analytics records, temporary pairing codes, webhook events, and AI usage events may be kept for shorter or longer periods depending on operational, security, and legal needs.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to the processing of your personal information. You may also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with a data protection authority.

You can update many details directly in Pallet, disconnect integrations, remove team members, delete inventory content, or contact us for help. We may need to verify your identity before acting on a request. If your data is controlled by a business workspace rather than directly by Pallet, we may refer your request to that workspace owner.

Children

Pallet is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to Pallet, contact us so we can review and delete it where appropriate.

Changes to this policy

We may update this Privacy Policy as Pallet changes or as legal, technical, or business requirements evolve. When we make material changes, we will update the date above and may notify users through the app, by email, or by another reasonable method.

Contact

For privacy questions or requests, contact InnoByte OÜ at info@innobytes.io. Please include enough detail for us to understand your request and locate the relevant account or workspace.