Batchnook Privacy Policy
Effective date: upon publication · Last updated: July 10, 2026
Batchnook ("Batchnook," "we," "us") is operated by ARDEO LABS LLC, a Florida limited liability company. This policy explains what we collect, why, and what your rights are. It covers theBatchnook mobile and web apps, the Batchnook website, and support channels.
The short version: your data is yours. We don't sell it, we don't run ads, we don't use your content to train AI models, and you can export or delete everything at any time.
1. What we collect
Account information. Email address and authentication credentials (sign-in uses one-time email codes or sign-in links managed by our authentication provider).
Your business content. What you enter to run your maker business: materials, purchases and vendor names, recipes, products and product photos, batches, orders, prices, marketplace fee presets, and your business name and logo (used on report headers).
Receipt photos and import files. Photos of supplier receipts you submit for AI import (or receipt text you paste), and CSV/spreadsheet files you upload for migration.
Your customers are yours. Orders you record or import — including marketplace imports — are stripped of customer identity before storage: products, quantities, prices, and fees only. Orders from a connected Shopify store are stripped of customer-identity fields (name, email, address, phone) before storage, and your cost-of-goods ledger never holds customer identity at all. Customers who buy through your Batchnook storefront are your customers: we store their name, shipping address, email, and order history for you — visible only to you, exportable by you, deleted with your account (we keep only a minimal order-contact record where product-safety law requires it — held five years, used for recalls and nothing else). We never sell their data or surface them to anyone else. Buyers are also Batchnook users: they hold Batchnook accounts, and Batchnook may communicate with them and — under the consents and notices they accept from us — market Batchnook and the marketplace to them. Your customer records stay yours throughout; what this does not promise is exclusivity of the buyer relationship.
Storefront buyer information (only if you open a storefront). What an order needs and nothing more: the buyer's name, email address, shipping address, the items and prices ordered, the shipping option, any gift note or personalization they typed, and — only if they tick the box themselves — a marketing opt-in recorded for you. Card details go to Stripe on Stripe's own pages and never reach us. Storefront buyer records are kept separate from the imported and manually recorded orders above. If you import customer records from another platform, they wait in a review area you control: nothing joins your buyer records unless you accept it, linking or merging is only ever your explicit action, and an import never upgrades anyone's marketing consent — a subscriber status carries over only when the other platform recorded it, with its date. A record you accept is governed exactly like any other storefront buyer record: visible only to you, exportable by you, deleted with your account, and never sold or surfaced to anyone else.
Payment information. Subscription payments are processed by Stripe. We receive your subscription status only — we never receive or store card numbers or card details. Money from your sales settles to accounts you own. Sales you record or import never move through Batchnook at all. Orders through your Batchnook storefront are processed by Stripe under your own Stripe account — funds settle directly to you, never into a Batchnook balance — and the Batchnook platform fee is deducted from the transaction proceeds by Stripe — see section 4 of our Terms of Service.
Usage and device data. Product analytics events (screens used, features triggered), device type, OS version, and approximate region, collected via PostHog. Analytics events are keyed to a pseudonymous account identifier — linkable to your account, but carrying none of your business content. Crash and error diagnostics collected via Sentry.
Support communications. Emails you send to our support address.
2. How we use it
- Provide, maintain, and improve the service (including sync and backups).
- AI receipt import: receipt photos or text you submit are sent to Anthropic's API to be parsed into purchase line items. Results always land in a review queue for your approval — nothing is created without your confirmation. Under Anthropic's commercial API terms, your inputs and outputs are not used to train their models.
- Send you the emails the service requires (sign-in codes, receipts, security notices). Reminders like low-stock alerts are generated locally on your device, not from our servers. If you opt in, we also send a weekly digest of your shop's numbers — delivered from our servers as a push notification and/or email; you can turn either channel off in Settings, and every digest email carries a one-click unsubscribe.
- Measure aggregate product usage, diagnose crashes, prevent fraud and abuse, and comply with law.
We do not sell or rent personal information, we do not share it with third parties for their own advertising, and we send marketing email only if you opt in (unsubscribe anytime).
3. What is public, and what never is
Your business records — materials, purchases, batches, costs, margins, and reports — have no public or shareable pages. Reports you export (PDF/CSV) leave the app only when you share them yourself.
If you open a Batchnook storefront, the things you publish to it are public by design: your shop page and shop name, your listings, their photos, prices, and descriptions, and your shop's policies. That is the point of a storefront, and you decide what goes on it. Your buyers' information is never public, your costs and margins are never public, and nothing else about your account becomes public because you opened a shop.
4. Data on your device
Some things live only on your device: notification preferences and locally scheduled reminders (like low-stock alerts) are stored and generated on-device, and in-app help is bundled with the app. Creating and editing records requires a connection. Device-level protections (passcode, encryption) are governed by your device settings.
5. Where your data lives
Data is stored with Supabase (PostgreSQL and file storage) in the United States, encrypted in transit (TLS) and at rest. Access in our systems is enforced by row-level security scoped to your account.
6. How long we keep it
- While your account is active: we keep your content so the service works; export is available anytime (More → Export my data, JSON/CSV), on any plan, including after you cancel a subscription.
- If you delete your account: deletion starts with an offered export and a 7-day grace window (you can restore by signing back in). After the grace period, your content is permanently deleted, except minimal records we must keep for legal, tax, or security purposes (e.g., invoices).
- Your storefront customers: kept while your account is active, exported by you at any time (CSV), and deleted with your account — except the order-contact record below.
- Order contacts, five years (product-safety law). For each storefront order we keep a minimal record — buyer name, one contact address, the item, and the date — for five years from the order, and it survives account deletion and buyer deletion. It exists so that a product recall can reach the people who bought the product, which is what product-safety law requires of us and of you. It is used for that and nothing else, it is never used for marketing, and no one reads it in the ordinary running of the service.
- Safety reports and moderation decisions, five years. Reports, complaints, and the decisions we make on them are kept for five years and survive account deletion, so that a pattern stays answerable to a regulator or a court after the account is gone.
- Backups age out on a rolling schedule of no more than 30 additional days.
7. Your rights and choices
- Access & portability: export everything from More → Export my data — free on every plan.
- Correction: edit your content in the app.
- Deletion: delete your account in the app (More → Your data → Delete account), or email [email protected] from your account email and we'll do it. Deleting your account cancels any active subscription.
- Marketing opt-out: unsubscribe links in every non-transactional email.
- Your storefront customer list: export it as CSV from the app at any time, on every plan. It is yours; we never mail your buyers on our own behalf.
- If you bought from a Batchnook storefront: your order details belong to the shop you bought from, and we hold them for that shop. Email [email protected] and we will delete your name, contact address, and shipping address from that shop's customer list — everything except the five-year order-contact record described above, which product-safety law requires us to keep. You can ask us for a copy of what we hold about your orders the same way.
- State privacy rights: depending on where you live (e.g., California, Colorado, Virginia, Florida), you may have statutory rights to access, delete, correct, or obtain a copy of your personal information, and to non-discrimination for exercising them. We honor these requests for everyone, resident or not. We do not "sell" or "share" personal information as those terms are defined in the CCPA/CPRA.
To exercise any right: [email protected]. We verify requests via your account email and respond within the time required by applicable law (generally 45 days).
8. Children
Batchnook is a business tool for adults. It is not directed at children under 13 (or under 18 for account creation), and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
9. Security
Row-level security on every table, TLS everywhere, encryption at rest, scoped credentials, and no card data in our systems. No method of transmission or storage is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.
10. Service providers (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | US |
| Stripe | Subscription billing | US |
| Anthropic | Receipt reading (the photos and text you submit) | US |
| Resend | Transactional email (weekly digest edition, contact-form relay) | US |
| Cloudflare | Website hosting and DNS | US |
| Shopify | Order sync — and customer import, if you choose it — when you connect a Shopify store | Canada |
| PostHog | Product analytics | US |
| Sentry | Error and crash diagnostics | US |
| Expo (EAS) | App builds and notification delivery | US |
Each provider processes data only as needed to provide its service to us, under its own contractual data-protection commitments.
11. Changes
We'll post changes here and update the date above. For material changes, we'll notify you in the app or by email before they take effect.
12. Contact
ARDEO LABS LLC
[email protected]
Ardeo Labs LLC
5944 Coral Ridge Dr # 1017
Coral Springs, FL 33076
United States