Service operator summary: Nexvintrix provides and operates the service, and the Stintry application and related intellectual property are owned by Theunis Gerhardus Kerry and Nicolaas Jacobus Robbertse as co-owners of the application.
1. Introduction
Nexvintrix ("we", "us", "our") operates Stintry, the software-as-a-service platform and application, in connection with the application co-owners, Theunis Gerhardus Kerry and Nicolaas Jacobus Robbertse. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By accessing or using Stintry, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When an administrator creates your account, we collect:
- Username and display name
- Password (stored as a one-way bcrypt hash � we never store or see your actual password)
- Role assignment (Admin or Scanner)
- Two-factor authentication secrets (encrypted, if 2FA is enabled)
2.2 Company & Organisation Data
- Company name, tagline, and logo uploaded during setup
- SAP Business One connection details (if integration is configured)
2.3 Inventory & Operational Data
- Product information (barcodes, names, descriptions, prices, categories, and related catalogue fields)
- Bin and warehouse locations, planogram and layout data where configured
- Stock count entries, spot counts, transfers, GRV / receipt sessions, and batch assignments
- Landed-cost and purchasing inputs where used
- Operational reports and analytics outputs (for example stock ageing, dead-stock, and dashboard metrics)
- Admin dashboard layout preferences and named dashboard profiles
- Calendar / operational event entries created in the Service
- Floor and stock request records and related workflow status
- Product images captured or uploaded via the Service (including AI image tooling where enabled)
- Audit trail logs (user actions with timestamps)
2.4 Technical & Usage Data
- IP addresses (for rate limiting and security)
- Browser type and device information
- Camera permission and scan-session metadata when a user explicitly opens barcode scanning or image capture flows
- Session data and authentication tokens
- Server performance metrics (CPU, memory, uptime)
- Error logs and crash reports
2.5 Central Hub Data (Multi-Tenant Deployments)
If your instance is connected to a Central Hub, the following is transmitted via periodic heartbeats:
- Instance identifier and URL
- System health metrics (CPU, memory, database status)
- Aggregate counts (products, users, bins, daily scans)
- Application version and environment details
3. Legal Basis for Processing
In accordance with the Protection of Personal Information Act (POPIA), 2013, we process personal information on one or more of the following lawful bases:
- Consent � Where you have given explicit consent (e.g., creating an account, enabling integrations)
- Contract � Processing necessary to perform a contract with you or your organisation (e.g., providing the Service under a subscription agreement)
- Legitimate Interest � Processing necessary for our legitimate interests, such as securing the Service, preventing fraud, and improving functionality, provided such interests are not overridden by your rights
- Legal Obligation � Processing required to comply with applicable law (e.g., tax records, court orders)
4. How We Use Your Information
We use the collected information to:
- Provide the Service � Enable inventory management, stock counting, transfers, landed cost and retail analytics, dashboards, and reporting
- Authenticate users � Verify identity via passwords and optional 2FA
- Enforce security � Rate limiting, session management, brute-force protection, and audit logging
- Manage subscriptions � Enforce plan limits and feature access via the heartbeat system
- Generate reports � Stock reports, variance analysis, movement reports as requested by administrators
- Provide support � Diagnose technical issues using system metrics and error logs
- Improve the Service � Analyse usage patterns to enhance features and performance
5. Data Storage & Security
5.1 Storage
- Cloud deployments: Data is stored in PostgreSQL databases hosted on Railway or your chosen cloud provider
- Local/Desktop deployments: Data is stored in local JSON files and/or a local PostgreSQL database
- Product images: Stored in the database or local filesystem, with auto-generated thumbnails
5.2 Security Measures
- Encryption in transit: All cloud deployments use HTTPS/TLS encryption. Local deployments auto-generate SSL certificates
- Password hashing: All passwords are hashed using bcrypt with salt rounds � passwords are never stored in plaintext
- Session security: HTTP-only, secure, SameSite cookies with session regeneration on login
- Rate limiting: Brute-force protection on login endpoints (15 attempts per 15 minutes per IP)
- Input sanitisation: All user inputs are sanitised to prevent injection attacks
- Parameterised queries: All database queries use parameterised statements to prevent SQL injection
- CORS protection: Cross-origin requests restricted to authorised domains
- Content Security Policy: CSP headers restrict script execution sources
- Two-Factor Authentication: Optional TOTP-based 2FA for enhanced account security
6. Data Sharing & Disclosure
We do not sell, rent, or trade your personal or business data to third parties.
We may share data only in the following circumstances:
- With your consent � When you explicitly authorise data sharing
- Service providers � Cloud hosting providers (Railway, Render) that host your data under their own privacy policies
- Legal requirements � When required by law, court order, or government regulation
- Business transfer � In connection with a merger, acquisition, or asset sale (with prior notice)
- SAP Integration � When you configure SAP B1 integration, product data is synced with your SAP system as directed
7. Data Retention
- Account data is retained for as long as the account exists. Administrators can delete user accounts at any time.
- Inventory data (products, stock logs, transfers) is retained until manually cleared or a backup is restored.
- Audit trail entries are retained per your configured retention policy.
- Session data expires after 7 days of inactivity.
- Rate limiting records are automatically purged every 5 minutes.
- Backups are retained per your configured retention schedule (default: as configured by administrator).
8. Data Breach Notification
In accordance with POPIA Section 22, in the event of a data breach that compromises the confidentiality, integrity, or availability of personal information:
- We will notify the Information Regulator as soon as reasonably possible after becoming aware of the breach
- We will notify affected data subjects (via email or in-app notification) where the breach is likely to result in a risk to their rights
- Notifications will include: a description of the breach, the types of personal information involved, the measures taken or proposed to address the breach, and recommendations for affected individuals to mitigate potential harm
- We will document all breaches internally, including those that do not meet the notification threshold, as part of our security incident response records
9. Your Rights
Depending on your jurisdiction (including POPIA in South Africa, GDPR in the EU), you may have the right to:
- Access � Request a copy of your personal data
- Correction � Request correction of inaccurate data
- Deletion � Request deletion of your account and associated data
- Portability � Request your data in a portable format (CSV export is available)
- Objection � Object to certain types of data processing
- Restrict processing � Request limitation of data processing
To exercise these rights, contact your system administrator or email us at the address below.
10. Complaints
If you believe your personal information has been processed in violation of POPIA, you have the right to lodge a complaint with the Information Regulator (South Africa):
- Website: www.justice.gov.za/inforeg
- Email: complaints.IR@justice.gov.za
We encourage you to contact us first so that we can attempt to resolve your concern directly.
11. Automated Decision-Making
Stintry does not use automated decision-making or profiling that produces legal effects or similarly significant effects on data subjects. All decisions regarding inventory, stock counts, and user accounts are made by authorised human operators through the Service interface.
12. Cookies & Local Storage
- Session cookie: A single HTTP-only session cookie is used for authentication. It is essential for the Service to function.
- Local storage: Used to store user preferences (dark mode, language selection, dashboard layout and named dashboard profiles) and offline scan queue data.
- No tracking cookies: We do not use analytics, advertising, or third-party tracking cookies.
13. Children's Privacy
Stintry is a business application not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
14. International Data Transfers
If you use cloud-hosted deployments, your data may be processed in data centres outside your country of residence. Railway and Render operate data centres in the United States. By using the Service, you consent to such transfers.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last Updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.
16. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:
- Company: Nexvintrix
- Application Co-Owners: Theunis Gerhardus Kerry and Nicolaas Jacobus Robbertse
- Email: support@nexvintrix.co.za
- Information Officer: support@nexvintrix.co.za
- Application: Stintry v3.16.0