Privacy Policy
Last updated: 2026-06-02
StackCube (operated by Waveon, "we" or "us") processes personal information in accordance with applicable privacy laws and this Privacy Policy.
1. Information We Process
We may process information for consultations, trials, account administration, order intake, and customer support.
- Consultation and trial data: name, company, phone number, email, inquiry details, industry, and adoption context.
- Account and workspace data: email, name, phone number, company, role, permissions, login identifier, password hash, organization settings, plan, and service status.
- Order intake data: dealer or customer names, contact persons, emails, phone numbers, addresses, business registration numbers, order numbers, order channels, item names, item codes, options, quantities, unit prices, amounts, shipping details, and memos.
- Source content and attachments: original email, chat messages, SMS, spreadsheet, PDF, image, purchase order, HTML body, sender, recipient, subject, received time, and attachments.
- AI analysis data: extracted order lines, item candidates, confidence scores, warnings, model name, and analysis timestamp.
- Automatically collected data: IP address, cookies, device and browser information, referral path, usage time, click and scroll events, logs, and security events.
2. How We Collect Information
- Website consultation, brochure request, trial request, signup, and settings forms.
- Information entered or uploaded by administrators and users.
- Orders submitted through order pages, email, chat, SMS, spreadsheets, PDFs, and images.
- Records generated during email intake, file upload, order analysis, admin actions, and customer support.
- Analytics and advertising tools such as Google Analytics, Google Tag Manager, Microsoft Clarity, and Meta Pixel.
3. Purposes of Processing
- Responding to inquiries, providing brochures, demos, and trial access.
- Creating accounts, authenticating users, managing roles, workspaces, and dealers.
- Receiving dealer orders, creating order queues, matching items and prices, reviewing, approving, editing, rejecting, and preparing order data for fulfillment and settlement.
- Reviewing original order content, detecting duplicates or missing information, and extracting order lines with AI assistance.
- Providing customer support, incident response, security monitoring, and fraud prevention.
- Improving service quality, usability, and functionality.
- Marketing and ad measurement, only where permitted or consented to.
- Complying with legal obligations and resolving disputes.
4. AI Processing and Model Training
To improve order processing efficiency, we may send order text, HTML body, attachments, dealer information, item information, and shipping information to an external AI API for order line extraction, item candidate preparation, multi-order separation, and missing-information checks.
We do not use customer item names, dealer information, order data, purchase orders, or attachments to train StackCube's own AI models.
OpenAI's API Platform does not use API inputs or outputs to train or improve OpenAI models by default. We do not provide customer data to external AI providers for model training without separate consent.
External AI providers may retain API inputs, outputs, or related logs for limited periods to provide the service and prevent abuse. Under OpenAI's default API policy, abuse monitoring logs may be retained for up to 30 days, and feature-specific application state retention may apply.
Customers may request adjustment or deactivation of AI order analysis. AI results are review aids and do not automatically finalize orders.
5. Retention and Deletion
- Consultation and trial data: until inquiry handling is complete and for up to 3 years, or until deletion is requested.
- Account and organization data: deleted within 30 days after service termination, except where retention is required for billing, disputes, or law.
- Dealer, order, item, and shipping data: retained during service use and deleted within 30 days after termination or deletion request, subject to exceptions.
- Attachments and original source content: retained for order review during service use and deleted after termination or deletion request.
- Backup data: deleted on a rolling basis within up to 90 days, except where needed for security, recovery, or legal obligations.
- Access and security logs: retained for at least 3 months or as needed for security and dispute response.
- Contract and payment records: retained for periods required by applicable law.
- Advertising and analytics cookies: retained for up to 2 years or according to each tool's policy and settings.
6. Deletion Method
- Electronic files: deleted or made inaccessible in a manner that makes recovery difficult.
- Databases: deleted by identifier, anonymized, or access-disabled.
- Attachment and source files: deleted from storage or made inaccessible.
- Paper documents, if any: shredded or destroyed.
7. Third-Party Disclosure
We do not disclose personal information to third parties without consent, except where consent has been provided, required by law, or necessary for service processing through processors or international transfers described in this Policy.
8. Processors
We may entrust processing to the following providers. Actual providers may vary depending on enabled features, contract scope, and operating environment.
| Processor | Purpose |
|---|---|
| Waveon | Tenant app hosting, app build, and operating infrastructure |
| Cloudflare | DNS, CDN, security, and web traffic proxy |
| Vercel or equivalent cloud hosting provider | Web application and API hosting |
| Amazon Web Services | Data storage, attachment storage, inbound email, queues, backups, and cloud infrastructure |
| OpenAI | AI-based extraction and classification of order source content and attachments |
| Google LLC | Analytics and advertising measurement, including Google Analytics, Google Tag Manager, and Google Ads |
| Microsoft Corporation | Usability analytics through Microsoft Clarity |
| Meta Platforms, Inc. | Advertising measurement through Meta Pixel |
| Slack Technologies, LLC | Consultation and operational notifications |
| Make or equivalent automation tools | Consultation intake and workflow automation |
| Sentry or equivalent error monitoring tools | Error collection, incident analysis, and reliability improvement |
| Stripe, Danal, and payment processors | Payments, billing, settlement, and fraud prevention |
| Messaging and address API providers | Messaging channel integrations, address search, and order channel integrations |
9. International Transfers
Personal information or service data may be processed internationally as necessary to provide the service.
| Recipient | Country | Data | Purpose | Timing and Method | Retention |
|---|---|---|---|---|---|
| OpenAI | United States and other infrastructure locations | Order source content, attachments, dealer, item, shipping, AI request and response data | AI order extraction and classification | Network transfer when AI analysis runs | According to provider policy and contract. Not used for model training by default |
| Cloudflare | United States and other global infrastructure locations | IP address, request headers, access logs, security events | DNS, CDN, security, and proxy | Automatic transfer during website and service access | According to provider policy and contract |
| Google, Microsoft, Meta | United States and other provider infrastructure locations | Cookies, device information, visit and usage records, ad identifiers | Analytics, ad measurement, and usability improvement | Automatic transfer when tools run, subject to consent and settings | According to each provider's policy and settings |
| Slack, Make, Sentry, and operational tools | United States, EU, and other infrastructure locations | Consultation data, operational notifications, error logs, identifiers | Support, automation, and error analysis | Network transfer when relevant events occur | According to provider policy and contract |
| Payment processors | Provider infrastructure locations | Payment identifiers, billing information, transaction status | Payment processing, settlement, and fraud prevention | Transfer during payment or billing processing | According to law and provider policy |
10. Security Measures
- Least-privilege access and role-based access control for personal information and order data.
- Administrator authentication, password hashing, and session management.
- HTTPS/TLS encryption in transit.
- Cloud storage and database access controls.
- Separated attachment storage paths and limited access methods such as signed URLs.
- Security, error, and operational logs for anomaly detection.
- Access limitations and supervision for personnel and processors.
- Backup and recovery procedures for resilience and data protection.
11. Cookies and Similar Technologies
We use cookies and similar technologies for website operation, service improvement, analytics, and advertising measurement. You may disable or delete cookies through browser settings, but blocking essential cookies may limit login, security, and order processing features.
12. Your Rights
You may request access, correction, deletion, suspension of processing, or withdrawal of consent. We process requests after identity verification as required by law. Deletion or suspension may be limited where retention is required by law, contract performance, or dispute response.
13. Children
StackCube is a B2B service for businesses and work users. We do not knowingly provide the service to children under 14. If we identify such data, we will delete it without delay.
14. Privacy Contact
- Privacy Officer: StackCube Privacy Team
- Email: support@stackcube.io
15. Changes
This Policy may be updated due to changes in law, service, processors, or security practices. Material changes will be announced through the website, email, or other appropriate methods.