Privacy policy
What we hold, why we hold it, and when it is deleted. Every claim about the software is enforced by a test, not by good intentions.
Last updated: 8 October 2026
Who is responsible
Tigran Avakov, a self-employed individual, Mirzo-Ulugbek 45A, 100007 Tashkent, Uzbekistan, trading as WareAudit, decides how the data described here is processed. Write to support@wareaudit.com or call +998 90 167 66 72 with any question about it.
What we collect
- Your email address, to create the account and to send sign-in links. Your password, stored only as a salted hash that cannot be turned back into the password.
- Invoice lines from your provider: order number, SKU, warehouse, carrier, shipping method, weight, box size, fee type and amount, and for each shipping label the destination country and the first three characters of its postal code (a US ZIP3 or a Canadian FSA). These are what a finding is proved from: a label's zone is looked up from those three characters.
- Your rate card, as you enter it, and the findings we compute from it.
- A provider API token, if you choose to connect one instead of uploading files.
- Duty invoices you upload: the invoice PDF and its Tax and Duties breakdown as received, encrypted and deleted after 13 months, and the rows behind each duty finding.
- Bills you forward by email. If you forward a bill to your WareAudit address, we keep the CSV files it carries, the columns we read from an Excel workbook, and a duty invoice PDF with its Tax and Duties breakdown as received, exactly like an upload (encrypted, deleted after 13 months). Before that the attached files wait encrypted for up to 7 days: a ZIP archive while it is unpacked, a file that waits until we know the currency of your bills, and a different version of a bill you already have until you use or discard it. For every email that reaches the address, including one we turn away, we keep a record: the sender addresses, the subject, the time it arrived, the size of the email, a fingerprint of its Message-ID, the results of the sender checks, and, for an email we accept, the names, sizes and fingerprints of the attached files. If a file has to wait until we know the currency of your bills, we also keep that email's Message-ID with the file, only so that our reply lands in the same thread, and delete it when the file is processed or closed after 7 days. An email over the hourly or daily limit of the address is turned away without a record. That record stays while your account is open, so you can see what we received. Other attachments and the email body are never stored.
- Documents you send for dispute support, if you use it: your provider's replies, your agreement and rate cards, and order files from your warehouse system. We use them only for your dispute. Order files should not include shopper names or addresses; if one does, we delete those columns when it arrives.
- Basic usage counts: audits run, dollars found, plan state. We use these to see whether the product works, not to profile anyone.
What we deliberately never collect
Shopper names, street addresses, cities, full postal codes, phone numbers and shopper email addresses are dropped while the invoice is being parsed, before anything is written to the database. Of a shipping address we keep only the country and the first three characters of the postal code, which is enough to look up a shipping zone. Only the fields on a fixed list survive.
This is not a promise about intent. An automated test deletes that list and fails the build if the data survives, so the guarantee cannot quietly rot.
Why we are allowed to hold it
We process this data to perform the contract you entered into when you signed up: without the invoice lines there is no audit. Usage counts rest on our legitimate interest in knowing whether the service works, and they carry no personal data.
How long we keep it
- Raw invoice files and API responses: 13 months, then deleted. They are stored encrypted with a separate key per object, and that key is itself encrypted by a master key kept apart from the data.
- Invoice lines, the charges we read from each invoice: the audited month and the six months before it stay in the database, where the checks read them. Older months move into an archive, encrypted the same way as raw files, and stay there while your account is open.
- Findings, evidence, reports and dispute letters stay while your account is open. They hold no personal data.
- Tokens are encrypted the same way and are deleted when you disconnect the provider. The interface only ever shows the last four characters.
- Billing records are held by our payment provider for as long as tax law requires, which is outside our control.
- When your subscription ends, the account closes and everything above that we hold is deleted 30 days later. If you ask us to delete it, we do not wait for that.
- When a trial ends without a subscription, the account closes 90 days after the trial ended, and everything above is deleted 30 days after that. We send one reminder to the account email address 14 days before it closes. Picking a plan before then, or a trial extension we agree with you, keeps the account open.
- A one-off audit without a subscription is treated the same way, counting from the day we deliver the report, or from the purchase if there is no report yet: the account closes 90 days later, with the same reminder, and a plan or another one-off audit before then keeps it open.
- Invoices sent for a free audit: if we set up an account from them and never invite you to it, the account and everything from those files are deleted 120 days after we set it up.
Who else touches it
- Cloudflare runs the application, the database, the object storage and the outgoing email.
- Paddle is the merchant of record and handles payment, tax and receipts. We never see your card details.
That is the entire list for WareAudit itself. We do not sell data, do not share it with advertisers, and do not train models on it. There are no models in the audit core at all, only deterministic rules.
Dispute support, if you use it. You send us your provider's replies and the files they refer to by email; our mailbox is hosted by Zoho. Our team works on them with our own tools and with document-processing software from a provider whose business terms do not allow it to train on your files. We keep them on computers with encrypted disks and delete them within 30 days after dispute support ends.
Cookies
One cookie, set after you sign in, which keeps you signed in. There is no analytics tracker, no advertising pixel and no third party script on this site, which is why you were never asked to dismiss a consent banner.
Your rights
Ask us and we will send you everything we hold about your account, correct anything wrong in it, or delete the account and its data. Deletion is real deletion, not a hidden flag.
We answer within 30 days and usually within one business day. If you are in the UK, the EU or another region with a data protection authority, you may complain to it, though we would rather you told us first and gave us the chance to fix the problem.
Where the data lives
The application runs on Cloudflare infrastructure distributed across regions, so data may be processed outside your country. Cloudflare and Paddle both operate standard contractual clauses for international transfers.