← StackCube

Privacy Policy

Last updated: 2026-06-02

StackCube (operated by Waveon, "we" or "us") processes personal information in accordance with applicable privacy laws and this Privacy Policy.

1. Information We Process

We may process information for consultations, trials, account administration, order intake, and customer support.

  • Consultation and trial data: name, company, phone number, email, inquiry details, industry, and adoption context.
  • Account and workspace data: email, name, phone number, company, role, permissions, login identifier, password hash, organization settings, plan, and service status.
  • Order intake data: dealer or customer names, contact persons, emails, phone numbers, addresses, business registration numbers, order numbers, order channels, item names, item codes, options, quantities, unit prices, amounts, shipping details, and memos.
  • Source content and attachments: original email, chat messages, SMS, spreadsheet, PDF, image, purchase order, HTML body, sender, recipient, subject, received time, and attachments.
  • AI analysis data: extracted order lines, item candidates, confidence scores, warnings, model name, and analysis timestamp.
  • Automatically collected data: IP address, cookies, device and browser information, referral path, usage time, click and scroll events, logs, and security events.

2. How We Collect Information

  • Website consultation, brochure request, trial request, signup, and settings forms.
  • Information entered or uploaded by administrators and users.
  • Orders submitted through order pages, email, chat, SMS, spreadsheets, PDFs, and images.
  • Records generated during email intake, file upload, order analysis, admin actions, and customer support.
  • Analytics and advertising tools such as Google Analytics, Google Tag Manager, Microsoft Clarity, and Meta Pixel.

3. Purposes of Processing

  • Responding to inquiries, providing brochures, demos, and trial access.
  • Creating accounts, authenticating users, managing roles, workspaces, and dealers.
  • Receiving dealer orders, creating order queues, matching items and prices, reviewing, approving, editing, rejecting, and preparing order data for fulfillment and settlement.
  • Reviewing original order content, detecting duplicates or missing information, and extracting order lines with AI assistance.
  • Providing customer support, incident response, security monitoring, and fraud prevention.
  • Improving service quality, usability, and functionality.
  • Marketing and ad measurement, only where permitted or consented to.
  • Complying with legal obligations and resolving disputes.

4. AI Processing and Model Training

To improve order processing efficiency, we may send order text, HTML body, attachments, dealer information, item information, and shipping information to an external AI API for order line extraction, item candidate preparation, multi-order separation, and missing-information checks.

We do not use customer item names, dealer information, order data, purchase orders, or attachments to train StackCube's own AI models.

OpenAI's API Platform does not use API inputs or outputs to train or improve OpenAI models by default. We do not provide customer data to external AI providers for model training without separate consent.

External AI providers may retain API inputs, outputs, or related logs for limited periods to provide the service and prevent abuse. Under OpenAI's default API policy, abuse monitoring logs may be retained for up to 30 days, and feature-specific application state retention may apply.

Customers may request adjustment or deactivation of AI order analysis. AI results are review aids and do not automatically finalize orders.

5. Retention and Deletion

  • Consultation and trial data: until inquiry handling is complete and for up to 3 years, or until deletion is requested.
  • Account and organization data: deleted within 30 days after service termination, except where retention is required for billing, disputes, or law.
  • Dealer, order, item, and shipping data: retained during service use and deleted within 30 days after termination or deletion request, subject to exceptions.
  • Attachments and original source content: retained for order review during service use and deleted after termination or deletion request.
  • Backup data: deleted on a rolling basis within up to 90 days, except where needed for security, recovery, or legal obligations.
  • Access and security logs: retained for at least 3 months or as needed for security and dispute response.
  • Contract and payment records: retained for periods required by applicable law.
  • Advertising and analytics cookies: retained for up to 2 years or according to each tool's policy and settings.

6. Deletion Method

  • Electronic files: deleted or made inaccessible in a manner that makes recovery difficult.
  • Databases: deleted by identifier, anonymized, or access-disabled.
  • Attachment and source files: deleted from storage or made inaccessible.
  • Paper documents, if any: shredded or destroyed.

7. Third-Party Disclosure

We do not disclose personal information to third parties without consent, except where consent has been provided, required by law, or necessary for service processing through processors or international transfers described in this Policy.

8. Processors

We may entrust processing to the following providers. Actual providers may vary depending on enabled features, contract scope, and operating environment.

ProcessorPurpose
WaveonTenant app hosting, app build, and operating infrastructure
CloudflareDNS, CDN, security, and web traffic proxy
Vercel or equivalent cloud hosting providerWeb application and API hosting
Amazon Web ServicesData storage, attachment storage, inbound email, queues, backups, and cloud infrastructure
OpenAIAI-based extraction and classification of order source content and attachments
Google LLCAnalytics and advertising measurement, including Google Analytics, Google Tag Manager, and Google Ads
Microsoft CorporationUsability analytics through Microsoft Clarity
Meta Platforms, Inc.Advertising measurement through Meta Pixel
Slack Technologies, LLCConsultation and operational notifications
Make or equivalent automation toolsConsultation intake and workflow automation
Sentry or equivalent error monitoring toolsError collection, incident analysis, and reliability improvement
Stripe, Danal, and payment processorsPayments, billing, settlement, and fraud prevention
Messaging and address API providersMessaging channel integrations, address search, and order channel integrations

9. International Transfers

Personal information or service data may be processed internationally as necessary to provide the service.

RecipientCountryDataPurposeTiming and MethodRetention
OpenAIUnited States and other infrastructure locationsOrder source content, attachments, dealer, item, shipping, AI request and response dataAI order extraction and classificationNetwork transfer when AI analysis runsAccording to provider policy and contract. Not used for model training by default
CloudflareUnited States and other global infrastructure locationsIP address, request headers, access logs, security eventsDNS, CDN, security, and proxyAutomatic transfer during website and service accessAccording to provider policy and contract
Google, Microsoft, MetaUnited States and other provider infrastructure locationsCookies, device information, visit and usage records, ad identifiersAnalytics, ad measurement, and usability improvementAutomatic transfer when tools run, subject to consent and settingsAccording to each provider's policy and settings
Slack, Make, Sentry, and operational toolsUnited States, EU, and other infrastructure locationsConsultation data, operational notifications, error logs, identifiersSupport, automation, and error analysisNetwork transfer when relevant events occurAccording to provider policy and contract
Payment processorsProvider infrastructure locationsPayment identifiers, billing information, transaction statusPayment processing, settlement, and fraud preventionTransfer during payment or billing processingAccording to law and provider policy

10. Security Measures

  • Least-privilege access and role-based access control for personal information and order data.
  • Administrator authentication, password hashing, and session management.
  • HTTPS/TLS encryption in transit.
  • Cloud storage and database access controls.
  • Separated attachment storage paths and limited access methods such as signed URLs.
  • Security, error, and operational logs for anomaly detection.
  • Access limitations and supervision for personnel and processors.
  • Backup and recovery procedures for resilience and data protection.

11. Cookies and Similar Technologies

We use cookies and similar technologies for website operation, service improvement, analytics, and advertising measurement. You may disable or delete cookies through browser settings, but blocking essential cookies may limit login, security, and order processing features.

12. Your Rights

You may request access, correction, deletion, suspension of processing, or withdrawal of consent. We process requests after identity verification as required by law. Deletion or suspension may be limited where retention is required by law, contract performance, or dispute response.

13. Children

StackCube is a B2B service for businesses and work users. We do not knowingly provide the service to children under 14. If we identify such data, we will delete it without delay.

14. Privacy Contact

  • Privacy Officer: StackCube Privacy Team
  • Email: support@stackcube.io

15. Changes

This Policy may be updated due to changes in law, service, processors, or security practices. Material changes will be announced through the website, email, or other appropriate methods.

Contact: support@stackcube.io