Privacy policy
What we hold, why we hold it, and when it is deleted. Every claim here is enforced by a test, not by good intentions.
Last updated: 23 August 2026
Who is responsible
Tigran Avakov, trading as WareAudit and based in Uzbekistan, decides how the data described here is processed. Write to support@wareaudit.com or call +998 90 167 66 72 with any question about it. Postal address: Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan.
What we collect
- Your email address, to create the account and to send the one time sign in link. There is no password, so there is no password to leak.
- Invoice lines from your provider: order number, SKU, warehouse, carrier, zone, weight, fee type and amount. These are what a finding is proved from.
- Your rate card, as you enter it, and the findings we compute from it.
- A provider API token, if you choose to connect one instead of uploading files.
- Basic usage counts: audits run, dollars found, plan state. We use these to see whether the product works, not to profile anyone.
What we deliberately never collect
Shopper names, shipping addresses, phone numbers and shopper email addresses are dropped while the invoice is being parsed, before anything is written to the database. Only the fields on a fixed list survive.
This is not a promise about intent. An automated test deletes that list and fails the build if the data survives, so the guarantee cannot quietly rot.
Why we are allowed to hold it
We process this data to perform the contract you entered into when you signed up: without the invoice lines there is no audit. Usage counts rest on our legitimate interest in knowing whether the service works, and they carry no personal data.
How long we keep it
- Raw invoice files and API responses: 90 days, then deleted. They are stored encrypted with a separate key per object, and that key is itself encrypted by a master key kept apart from the data.
- Findings and reports stay while your account is open. They hold no personal data.
- Tokens are encrypted the same way and are deleted when you disconnect the provider. The interface only ever shows the last four characters.
- Billing records are held by our payment provider for as long as tax law requires, which is outside our control.
Who else touches it
- Cloudflare runs the application, the database, the object storage and the outgoing email.
- Paddle is the merchant of record and handles payment, tax and receipts. We never see your card details.
That is the entire list. We do not sell data, do not share it with advertisers, and do not train models on it. There are no models in the audit core at all, only deterministic rules.
Cookies
One cookie, set after you sign in, which keeps you signed in. There is no analytics tracker, no advertising pixel and no third party script on this site, which is why you were never asked to dismiss a consent banner.
Your rights
Ask us and we will send you everything we hold about your account, correct anything wrong in it, or delete the account and its data. Deletion is real deletion, not a hidden flag.
We answer within 30 days and usually within one business day. If you are in the UK, the EU or another region with a data protection authority, you may complain to it, though we would rather you told us first and gave us the chance to fix the problem.
Where the data lives
The application runs on Cloudflare infrastructure distributed across regions, so data may be processed outside your country. Cloudflare and Paddle both operate standard contractual clauses for international transfers.