SKUantify

Privacy Policy

How SKUantify handles account data, customer inventory data, security records and service-provider processing.

Last updated 24 September 2026


1. Scope

This Privacy Policy applies to the public SKUantify website and the hosted SKUantify inventory-management application operated by Sky Arkanum. It explains what personal data we process, why we process it, who may receive it, how long we keep it, and the choices and rights available to you.

This policy does not replace a signed client agreement, order form, data processing addendum, or other contract. If a signed agreement gives a customer additional privacy protections, that agreement will apply to that customer in addition to this policy.

Because Sky Arkanum operates from the Philippines, this policy is intended to be read consistently with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules and applicable guidance of the National Privacy Commission. Additional privacy laws may also apply to particular customers, users or data subjects depending on their location and the processing involved.

2. Who is responsible for the data

SKUantify is operated by Sky Arkanum, operating from the Philippines. For general business enquiries, contact us at info@skuantify.com. For privacy, personal-data, data-subject-rights or security-related enquiries, contact privacy@skuantify.com.

Our role depends on the data involved:

  • For account, security, support and website-contact data, Sky Arkanum decides why and how the data is processed. Under Philippine privacy terminology, we act as the Personal Information Controller; in other jurisdictions, the equivalent term is usually controller.
  • For personal data that a customer puts into its SKUantify workspace, such as a supplier contact person or information about its staff, the customer normally decides why that information is being processed. In that situation the customer is the controller and Sky Arkanumprocesses the data to provide SKUantify as a Personal Information Processor / processor.

3. Personal data we process

SKUantify is an inventory system, not a consumer profiling service. We limit collection to information needed to operate, secure and support the service or information a customer chooses to place in its workspace.

CategoryExamplesWhy it is processed
Account and identity dataName, email address, password hash, password-change timestamp, last-login timestamp, membership, role and permitted locationsCreate and secure accounts, authenticate users, enforce permissions and provide the service
Business configurationBusiness name, location names and addresses, currency, inventory settings and subscription planConfigure the customer workspace and apply agreed service limits
Inventory and operational dataProducts, variants, SKUs, barcodes, categories, prices, costs, thresholds, stock levels, movement records, references, notes, stock counts, reports and product imagesProvide inventory management, monitoring, auditability, reporting and related workflows
Supplier/contact data entered by customersSupplier name, contact person, email, phone, address and notesProvide the supplier directory and product-supplier association features requested by the customer
Authentication and security dataInvitation/reset-token records, failed-sign-in or reset-request rate-limit keys, IP address and security timestampsPrevent abuse, protect accounts, investigate security events and operate authentication controls
Technical and operational logsIP address, user agent, request path/method, timestamps, error messages, diagnostic context and hosting logsOperate, troubleshoot, secure and maintain the service
CommunicationsEmail address, message content and attachments you send to usRespond to support, sales, migration, privacy and other enquiries

4. Passwords and authentication secrets

We do not store account passwords in readable form. Passwords are hashed with Argon2id before storage. Invitation and password-reset tokens are stored as hashes rather than as the original token. A password change or reset causes sessions issued before the change to be refused.

You are responsible for keeping your password and any valid invitation, reset link or authenticated device secure and for notifying us or your business administrator if you believe an account has been compromised.

5. Customer content and third-party personal data

A customer may enter personal data about people who are not direct SKUantify account holders, for example a supplier contact person. The customer is responsible for having a lawful reason to collect and use that information and for providing any notice required by law. We process that information only to provide and support SKUantify, follow the customer's lawful instructions, protect the service, or comply with law.

SKUantify is not designed to store patient records, government identity numbers, payment-card data, biometric data, criminal records, children's data, or other sensitive personal information unrelated to inventory operations. Customers should not place such information in free-text fields, notes, images or references unless it is genuinely necessary, lawful and covered by appropriate safeguards and an agreed scope with us.

6. What we do not do with personal data

  • We do not sell or rent personal data.
  • We do not share personal data with advertising networks for their own targeted-advertising purposes.
  • At the date of this policy, we do not embed advertising pixels, session-replay tools or third-party behavioral analytics in the public website or SKUantify application.
  • We do not use customer inventory content to train our own AI models.
  • SKUantify currently has no self-service card checkout and does not collect payment-card numbers through the website or application.

7. Why we process personal data

We process personal data only where there is a lawful and legitimate reason to do so. Depending on the situation, that includes:

  • Providing a contract or requested service: creating accounts, operating workspaces, recording inventory activity, generating reports, providing support and administering an agreed plan.
  • Legitimate operational and security interests:preventing abuse, securing accounts, diagnosing errors, maintaining service reliability and protecting customers and the platform, provided those interests do not override applicable privacy rights.
  • Legal obligations: complying with valid legal, regulatory, tax, security or law-enforcement requirements.
  • Consent: where the law requires consent or where we specifically ask for it for an optional activity. We do not treat use of the service as blanket consent for unrelated processing.
  • Customer instructions: where we act as a processor for personal data placed in a customer workspace.

8. Cookies and similar technologies

The public marketing website does not intentionally use advertising or analytics cookies. The authenticated SKUantify application currently uses the following cookies:

  • skuantify_session — a signed authentication cookie used to keep a user signed in. In production it is HTTP-only, Secure, SameSite=Lax, scoped to the application, and expires after seven days.
  • skuantify_theme — stores only the user's light/dark appearance choice. It is SameSite=Lax and may remain for up to one year so the application can render the chosen theme on a later visit.

The SKUantify mobile app does not use cookies. After you sign in, it stores the same signed, seven-day authentication token in the device's secure storage (the Android Keystore or iOS Keychain) and sends it with each request to the server. It also stores your appearance choice (system, light or dark) on the device. Signing out removes the stored token from the device.

We do not currently use cookies for cross-site advertising. If we add optional analytics, advertising or other non-essential tracking later, we will update this policy and provide consent controls where required before enabling that processing.

9. Who receives personal data

We disclose personal data only to people or organizations that need it for a defined purpose, including authorized members of the customer's own workspace, service providers that help us operate SKUantify, professional advisers where necessary, and authorities where disclosure is legally required.

Our current core service providers are:

ProviderPurposeData involved
VercelHosting, server execution, network delivery, deployment and operational loggingNetwork/request metadata such as IP address and user agent, route and error context, and application data that passes through the hosted service while a request is processed
Neon (Databricks)Managed PostgreSQL database and database backup/recovery infrastructureAccount, business, inventory, supplier, transaction, stock-count and security records, plus product images stored by SKUantify
ResendTransactional password-reset email when production email is enabledRecipient name and email address, reset-email content and delivery metadata

Resend is used only when transactional email is configured. At present, the application uses it for self-service password-reset email. Contact messages sent to our public email address also pass through ordinary email providers used by the sender and by our business mailbox.

The application source supports an optional external error-reporting webhook. We will not enable a new production error-monitoring destination that receives personal data without first adding that provider to our maintained privacy/subprocessor information and applying appropriate access and data-protection controls.

10. International processing

Sky Arkanum is based in the Philippines. Our current primary application database is hosted in United States (AWS us-east-2). Our hosting and email providers and their subprocessors may process data in the United States and other countries where they operate.

When personal data is processed outside the Philippines, we remain responsible for our obligations under applicable privacy law and use service providers and contractual arrangements intended to provide appropriate protection for the data. Customers with specific residency or transfer requirements should raise them before onboarding so they can be assessed against the available infrastructure and contract.

11. How long we keep data

We do not keep every category for the same period. Retention is based on the purpose of the data and any contractual, security or legal need to preserve it.

  • Customer workspace and inventory data: kept while the customer account is active and for as long as needed to provide the service, complete an agreed handover/export, resolve disputes, meet legal obligations, or carry out a verified closure/deletion request.
  • Inventory ledger records: kept as part of the active customer workspace because the product is designed to preserve an auditable movement history. Corrections are normally recorded as new transactions rather than rewriting prior movements.
  • Authentication/security records: kept for the period reasonably needed to operate abuse-prevention and account-security controls. Expired or stale rate-limit records are pruned from the operational table; valid session tokens expire after seven days.
  • Invitation and reset records: invitations expire after seven days and password-reset links expire after 24 hours. Associated records may remain for account-security, audit or troubleshooting purposes until they are removed through normal account-data cleanup.
  • Support and business communications: kept for as long as reasonably necessary to answer the request, administer the customer relationship, document agreed decisions, or meet legal obligations.
  • Provider backups and operational logs: may persist for a limited period under the provider's backup, security and log-retention cycle even after live data is removed. Backup copies are not used as a separate source for ordinary business processing and are overwritten or expire under those systems' retention controls unless preservation is legally required.

A verified deletion or account-closure request will be handled without undue delay and within any deadline required by applicable law. We may retain only the minimum information that must be preserved for legal, accounting, fraud-prevention, security, dispute-resolution or other mandatory purposes, and will not use retained information for an unrelated purpose.

12. Data security

We use technical and organizational safeguards appropriate to the current MVP and the risks of the data we process. Current controls include password hashing with Argon2id, signed sessions, Secure/HTTP-only session cookies in production, password-change session invalidation, tenant-scoped authorization, role and location permissions, rate limiting, hashed one-time tokens, transactional inventory writes, server-side permission checks and controlled access to the production database.

Our infrastructure providers also maintain their own security controls. No internet service can promise absolute security, so we continuously review material security findings and remediate them according to risk.

13. Your privacy rights

Depending on where you live and our role in processing the data, you may have rights to be informed, access your personal data, correct inaccurate data, object to or restrict certain processing, request erasure or blocking, obtain data in a portable form, withdraw consent where consent is the basis of processing, and complain to a privacy regulator.

For personal data we control directly, send a request to privacy@skuantify.com. We may ask for information reasonably necessary to verify identity and prevent someone else from exercising your rights fraudulently.

If your personal data was placed in SKUantify by a customer organization and we process it only on that customer's behalf, please contact that organization first. We will reasonably assist the customer with valid data-subject requests as required by applicable law and the customer agreement.

A request may be limited or refused only where applicable law permits or requires it, for example where fulfilling the request would expose another person's data, conflict with a legal retention duty, undermine a valid fraud/security investigation, or concern data we are required to preserve for a legal claim. Where appropriate, we will explain the reason.

14. Data exports and corrections

SKUantify supports CSV export for inventory reports and printable report views where available. Customers may also ask us for reasonable assistance with account-level access or export requests that are not available through the product.

Account and catalogue information may be corrected through authorized product workflows. Inventory movement history is intentionally append-only: an inventory mistake is corrected through an authorized corrective transaction so that the historical record remains auditable.

15. Personal data breaches and security incidents

If we become aware of a security incident involving personal data, we will assess and contain it, preserve appropriate evidence, document the incident, and notify the affected customer, regulators and/or data subjects when notification is required by applicable law. Where Philippine mandatory breach-notification rules apply, required notices are made within the legally prescribed period based on the information available at the time.

16. Children

SKUantify is a business operations product and is not directed to children as a consumer service. We do not knowingly invite children to create personal SKUantify accounts for their own use. A customer that creates an account for a worker who is below the age of majority is responsible for ensuring that the account and any related processing are lawful and appropriate for that worker.

17. Automated decisions and profiling

SKUantify calculates inventory status, totals, valuation and operational alerts from business inventory data. It does not currently make automated decisions about a person that produce legal or similarly significant effects, and we do not profile people for advertising.

18. Mobile application

The SKUantify mobile app is a client for the same hosted service described in this policy. When you use it, you sign in to your existing SKUantify account (or create a business), and the app sends the account, catalogue, stock-movement and stock-count information you enter to the SKUantify server. That information is processed and stored exactly as described above for the web application, under the same roles and location permissions.

The app works online only: it does not keep a local copy of your inventory data or queue changes to send later. On the device it stores only your authentication token (in secure storage) and your appearance choice. The app requests internet access only. It does not request access to your camera, photos, contacts, location or microphone. It does not contain advertising, analytics or crash-reporting SDKs, and does not collect advertising or device identifiers.

Before the app begins collecting new device data, permissions or identifiers that are not already covered here, this policy will be updated and any required platform or consent disclosures will be added.

19. Changes to this policy

We may update this policy as SKUantify changes, our providers change, or legal requirements evolve. The date at the top will identify the current version. If a change materially expands the personal data we collect or materially changes how we use it, we will provide reasonable additional notice where required before the new processing takes effect.

20. Contact and complaints

Privacy questions, access requests, correction requests, deletion requests, complaints and security concerns can be sent to privacy@skuantify.com. General business, sales and service enquiries can be sent to info@skuantify.com.

If you are in the Philippines and believe your privacy rights have been violated, you may also raise a complaint with the National Privacy Commission. If another jurisdiction's privacy law applies to you, you may have the right to complain to the competent privacy or data-protection authority in that jurisdiction.