Legal

Privacy Policy

Last updated July 6, 2026

This is a draft policy describing FulfillOS’s actual data practices as accurately as we can state them. It has not been reviewed by a lawyer. Please have qualified legal counsel review it — particularly the sections on packing-station video and employee consent, which vary by jurisdiction — before relying on it.

What we collect

  • Account & organization data: your name, email, and the organization(s) you belong to.
  • Order data: synced from the store platforms you connect (currently WooCommerce and Shopify) — customer name, email, phone, billing/shipping address, and order line items.
  • Packing station video: recorded automatically during a packing session and linked to the order it belongs to. Audio is never recorded unless your organization explicitly turns that setting on.
  • Integration credentials: API credentials for the store, courier, and storage providers you connect. These are encrypted at rest and never stored or logged in plain text.
  • Usage and audit data: a record of actions taken in your organization (who packed what, who resolved which claim), and session cookies used solely to keep you signed in.

How we use it

Solely to provide the FulfillOS service: verifying packing sessions, storing and retrieving proof of what was packed, resolving claims, and maintaining your organization’s audit trail. We do not sell data, and we do not use your order or video data for advertising.

Where it’s stored, and with whom it’s shared

Packing videos are stored with the storage provider your organization chooses (Google Drive, OneDrive, Amazon S3, or Dropbox) — under your own organization’s account where applicable. Order data comes from, and stays associated with, the store platforms you connect. We don’t share your data with any other third party except the specific integrations and storage providers you set up yourself.

Data isolation and security

Every organization’s data is isolated at the database level — enforced by the database itself, not just filtered in application code — so one organization can never read another’s orders, videos, or claims. Integration credentials are encrypted with AES-256-GCM. All traffic is served over HTTPS.

Retention and deletion

Your organization controls its own video compression preset and retention. If you delete your organization, it enters a 15-day recovery window (in case that was a mistake) before it and everything in it — orders, videos, claims, members — is permanently purged.

Your rights

You can request access to, correction of, or deletion of your personal data by contacting us at gopiskt@gmail.com.

Children’s privacy

FulfillOS is a business tool and is not directed at, or intended for, children.

Changes to this policy

If this policy changes materially, we’ll update the date above and notify account administrators by email.

Contact

Questions about this policy: gopiskt@gmail.com