Legal

Privacy Policy

How Skuvelo handles the information you give us, the operational data in your workspace, and the personal information that flows through the systems you connect. Written in plain language, and written to stay accurate as the product grows.

Effective August 3, 2026 · Last updated August 3, 2026

Who we are

Skuvelo is a commerce operations platform for people who sell physical products — inventory, purchasing, orders, suppliers, and cash in one place.

Skuvelo is a registered trade name (DBA) of Ventral Ventures LLC, a Texas limited liability company. Ventral Ventures LLC is the entity responsible for the information described in this policy, and is the data controller for it. Where this policy says "we" or "Skuvelo," it means Ventral Ventures LLC.

Two kinds of data, two different roles

Almost every question about privacy at Skuvelo has a different answer depending on which of these two buckets the data falls into. It is worth reading this section before the rest.

Account Data

We decide how it is used (we are the controller).

Information about you and your organization as a Skuvelo customer: who signed up, who is on the team, billing details, support conversations, and how the product is used. We decide what to collect and why, so we are accountable for it.

Workspace Data

You decide how it is used (we act on your instructions).

Everything inside your workspace: your catalog, stock, orders, suppliers, costs, and anything imported from a system you connect or a file you upload. It is your data. We hold and process it to provide the product to you and to follow your instructions — we do not decide independently to use it for our own purposes.

Where a connected platform's own rules are stricter than this policy, we follow the stricter rule.

Account Data we collect

This is information about you — as a Skuvelo customer, or as someone who contacted us before becoming one. We collect it to give you an account, bill you, support you, answer you, and keep the service running.

Identity and contact details
Name, work email, organization name, and — if you sign in through an identity provider — the account identifier that provider gives us. We store the provider's identifier rather than relying on your email address, because email addresses get reassigned to different people and identifiers do not.
Authentication records
Password hashes (never the password itself), session records, and sign-in events. We do not store credentials for the identity providers you sign in with.
Billing information
Subscription status, plan, and invoice history. When we begin collecting payment, card details will go directly to our payment processor and will never be stored on Skuvelo systems. No card is collected at signup.
Enquiry and waiting-list details
If you join our mailing list or request founding access before you are a customer, we collect what you tell us: your email, your company name, and — on the access form — the channels you sell on, your rough order and SKU volumes, the tools you use today, your team size, your timing, and the problem you are trying to solve. We record whether you consented to be contacted and which version of that consent you agreed to. We use it to reply to you, to decide who to onboard, and to send you updates if you asked for them. You can unsubscribe or ask us to delete it at any time.
Support and correspondence
Messages you send us, and our replies, so we can help you and keep a record of what was asked.
Service and diagnostic logs
Technical records generated as you use the product — request timing, error traces, connector sync outcomes — used to keep the service working and to investigate faults. We exclude credentials and, wherever it is technically possible, personal information from these logs.

Workspace Data we hold for you

This is your operating data. We describe it by what the record is, not by which system it came from or which part of Skuvelo produced it — so this list stays accurate as you connect new services and as we add features.

Catalog and item records
Products, variants, SKUs, barcodes, descriptions, attributes, and the relationships between listings on different channels.
Inventory and stock position records
Quantities, locations, bins, lots, serial numbers, movements, adjustments, counts, and transfers.
Demand, sales, and order records
Orders and order lines, sales history, returns, and cancellations — used to understand demand and to plan replenishment.
Fulfillment, shipment, and logistics records
Shipments, tracking, carriers, delivery status, and receiving activity.
Procurement and supply records
Suppliers and their contacts, purchase orders, costs, lead times, and terms.
Financial and settlement records
Payouts, settlements, fees, landed costs, and the accounting entries used to reconcile them.
Production and work-order records
Bills of material, work orders, routings, components, and production runs — where you use Skuvelo features that support manufacturing or assembly.
Warehouse operations records
Location and bin structures, picking, packing, putaway and replenishment tasks, cycle counts, and the device or scanner activity associated with them — where you use Skuvelo features that support warehouse operations.
Records about people in your operation
Your team members, supplier contacts, and other individuals whose details you or a connected system place in your workspace — typically a name, a work email, and a role.
End-customer personal information
Limited personal information about the people who buy from you, where an order or return cannot be processed without it. This category is handled under stricter rules — see the section on end-customer personal information below.

Why we process it

Providing the product
Running the features you use: syncing connected systems, maintaining stock positions, forecasting demand, generating purchase orders, reconciling settlements, and everything else you ask the product to do.
Keeping your account secure
Authenticating you, maintaining sessions, detecting abuse, and enforcing the separation between one customer's workspace and another's.
Support
Answering your questions and diagnosing problems. We access Workspace Data for support only when it is necessary to resolve an issue, and we prefer diagnostic records over customer data wherever they are sufficient.
Keeping the service reliable
Monitoring, debugging, capacity planning, backup, and disaster recovery.
Billing and administration
Invoicing, collecting payment, and maintaining the records a business is required to keep.
Improving Skuvelo
Understanding which features are used and where people get stuck, and improving the accuracy of our forecasting, planning, and analytics. For this we use Account Data together with aggregated and de-identified information derived from Workspace Data — statistics and patterns that cannot reasonably be attributed back to you, your business, or any individual. We never expose your data, or anything derived from it that could identify you or your business, to another customer or to the public, and we never use end-customer personal information for this purpose at all.
Talking to you about Skuvelo
Replying to enquiries, running the founding-access waiting list, and sending product updates to people who asked for them. We send marketing email only to people who opted in, every message has an unsubscribe link, and we do not sell or rent our list.
Legal obligations
Meeting tax, accounting, and regulatory requirements, and responding to lawful requests.

End-customer personal information

Some of what a sales channel returns is personal information about your buyer — most often a name and a delivery address, because a parcel cannot be sent without one. This is the most sensitive data the product touches, and it is governed by rules stricter than the rest of this policy. These rules apply to every sales channel you connect, present and future.

The important distinction: Skuvelo separates who bought something from what was bought. The buyer's identity is transient — it exists to get the parcel delivered and the return handled, and then it goes. The transaction is durable — it is your operating history, and it stays. Everything below follows from that split.

We take the minimum
We request only the fields needed to complete the operational task. Where a channel offers a restricted-access mechanism for personal information, we use it, and we request access only for the specific purposes that mechanism permits.
We use it only to do the work
Fulfilling and tracking orders, handling returns and disputes, calculating and remitting tax, producing legally required documents, and meeting legal obligations. Nothing else.
We never use it for marketing
We do not use end-customer personal information for advertising, retargeting, audience building, profiling, scoring, enrichment, resale, or any purpose of our own. We do not sell it or share it for cross-context behavioral advertising.
We remove the personal parts on a schedule — and keep your business records
Within 30 days of order delivery we strip the personally identifying fields from the order: buyer name, street address, email, phone, and any platform buyer identifier. We keep it longer only where a law requires us to, and then only for as long as that law requires and only for the purpose of complying with it.
Your sales history is not deleted
The order itself — what sold, how many, at what price, on what date, through which channel, and the region it shipped to — is your operating history and stays in your workspace for as long as you want it. Removing the buyer's identity does not remove the transaction. Forecasting, replenishment, and reporting need to know what sold and when; they never need to know who bought it, and Skuvelo is built so that they don't.
Returns keep their full record too
An RMA is business history, not personal information. The return, what came back, the quantity, the reason and classification, the disposition, the restocking fee, the refund and credit references, and the stock movements that resulted are all kept indefinitely — they are how you see return rates, supplier quality, and true margin. The 30-day rule applies to the buyer's contact details, never to the return record.
A late return still works
If a return is opened after the buyer's details have already been removed, we request them again from the sales channel for that specific order, at that moment, to handle that specific return — rather than holding everyone's details for a year in case a return arrives. Those details then follow the same 30-day rule from the day the return is resolved.
We never use it to train models for anyone else
End-customer personal information is never used to train, tune, or evaluate models or forecasts serving any other customer.
It stays encrypted and isolated
It is encrypted in transit, and confined to your workspace by database-level access controls, not merely by application logic — so one customer's records are not reachable from another customer's account even if application code is wrong.

If a connected platform's rules for its own data are stricter than these, the platform's rules govern.

Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose it only to these categories of recipient, and only for the purposes described above.

Infrastructure and hosting providers
The providers that run our servers, databases, and backups.
Connected Services you choose
When you connect a sales channel, accounting system, carrier, or other service, data moves between it and Skuvelo because you asked it to. What that provider then does with the data is governed by its own privacy policy, not this one.
Operational service providers
Providers that deliver transactional email, process payments, monitor errors, or provide customer support tooling on our behalf.
Professional advisers
Lawyers, accountants, and auditors, bound by professional confidentiality obligations.
Acquirers
If Skuvelo is involved in a merger, acquisition, financing, or sale of assets, data may transfer as part of that transaction. We will give you notice, and the recipient remains bound by commitments no less protective than these.
Legal and safety
Where we are legally required to disclose information, or where disclosure is necessary to investigate fraud or protect the rights and safety of people or property. Where we are permitted to tell you about a request, we will.

The current list of the providers that process data on our behalf is maintained at skuvelo.com/subprocessors.

How we protect it

  • Encryption in transit, and encryption at rest for credentials and sensitive records.
  • Envelope encryption for the access tokens that authorize connections to your systems. Those tokens are never written to logs or stored in readable form.
  • Tenant isolation enforced at the database level, so one customer's records are not reachable from another customer's account even if application code is wrong.
  • Access to production systems limited to the people who need it, with authentication required.
  • Credentials kept out of source code, logs, and configuration files.

No system is perfectly secure, and we will not claim otherwise. If a breach affects your data, we will notify you and any required regulator within the timeframes the law sets, and tell you what we know rather than the least we can get away with.

How long we keep it

Workspace Data
Kept while your account is active. When you close your account we delete or irreversibly anonymize it within 90 days, except where a longer period is legally required.
Identifying fields about end customers
Removed within 30 days of order delivery, as described above. This ceiling applies regardless of whether your account is still active, and it is not something you can extend by request — the platforms we connect to require it.
Order, return, and transaction history
Kept for as long as your account is active, with the identifying fields removed on the schedule above. This is your operating record — orders, returns, dispositions, costs, and the stock movements behind them. It drives forecasting, replenishment, seasonality, return-rate analysis, and reporting, and it is not subject to the 30-day rule, because once the identifying fields are gone it is no longer personal information.
Connection credentials
Deleted when you disconnect a service or close your account, whichever comes first.
Account and billing records
Retained for as long as tax and accounting law requires after your account closes — generally up to seven years.
Diagnostic logs
Kept for as long as they are useful for diagnosing faults and investigating security events. We exclude credentials from them, and exclude personal information wherever it is technically possible.
Backup copies
Where deleted data still exists in a backup copy, it is removed when that copy is cycled out. If we ever restore from a backup, data you asked us to delete is deleted again.

Your choices and rights

Depending on where you live, you may have some or all of the rights below. We extend them to every customer regardless of location, because maintaining two standards is how the lower one wins. We do not charge for exercising them, and we will not treat you differently for doing so — though, as the law allows, we may decline or charge for a request that is manifestly unfounded or excessive, or that would reveal another person's information.

Access and portability
Get a copy of your data in a machine-readable format. You can export report and list views as CSV from the product; for a complete copy of your workspace, ask us and we will provide one.
Correction
Fix inaccurate information — usually directly in the product.
Deletion
Ask us to delete your account and its data.
Objection and restriction
Object to or ask us to limit certain processing, where the law gives you that right.
Withdraw consent
Where we rely on consent, withdraw it at any time, without affecting what we did before you withdrew it.
Complain
Raise a complaint with your data protection authority. We would rather you came to us first, but it is your right either way.

Where the data in question is Workspace Data belonging to one of our customers, we act on that customer's instructions. If you are an individual whose information is in a seller's Skuvelo workspace, contact that seller — and if you cannot reach them, contact us and we will help.

What changes this policy, and what does not

Skuvelo adds sales channels, accounting systems, carriers, and product modules on an ongoing basis. Those additions do not, by themselves, change how we handle personal information. So that you can rely on this document rather than re-reading it every month, here is exactly what does and does not cause it to change.

Does not change this policy

  • Adding, changing, or retiring a Connected Service. The current list is maintained at /integrations.
  • Adding or retiring a Skuvelo module or feature that processes the categories of data already described above — including manufacturing and warehouse operations features.
  • Replacing one subprocessor with another that performs a function already described here. The current list is maintained at /subprocessors.
  • Adding, moving, or retiring a processing region or data center, as long as the protections described here travel with it. Current locations are maintained at /subprocessors.
  • Routine changes to how the product looks or works that do not change what data we hold or why.

Does change this policy

  • Processing a category of personal information not described above.
  • Processing personal information for a purpose not described above.
  • Disclosing personal information to a category of recipient not described above.
  • A change in our role — controller or processor — for a category of data.
  • A change to the retention periods stated above.

When one of those happens, we update this page and change the "Last updated" date. If the change is material, we notify account administrators — by email, in the product, or both — before it takes effect, so you have time to object or close your account.

The subprocessor list is a living document, kept current at /subprocessors. Customers who want advance warning of changes to it can ask us to notify them by email.

Cookies

Skuvelo uses only strictly necessary cookies — the ones that keep you signed in and keep your session secure. We do not use advertising cookies, tracking pixels, or third-party analytics that follow you across sites, and there is nothing here to opt out of because there is nothing running.

If that ever changes, we will update this section, and where the law requires consent we will ask for it before setting anything beyond what is strictly necessary.

Where your data is processed

Ventral Ventures LLC is a United States company, and Skuvelo runs on infrastructure in more than one country — today that includes data centers in the European Union alongside services operated from the United States. We expect to add regions as we grow. The current location of each provider is listed on our subprocessors page.

Wherever your data sits, the protections in this policy apply to it in full. We do not hold a region to a lower standard, and we do not move data somewhere in order to apply a weaker one.

Moving personal information across borders is lawful and routine, and we do it under the safeguards the law provides — including the European Commission's Standard Contractual Clauses and the UK Addendum where they apply. If you are in the United Kingdom, the European Economic Area, or Switzerland, those safeguards cover transfers out of your region.

We keep processing locations current on the subprocessors page rather than by reissuing this policy each time infrastructure moves. What changes there is the map; what does not change is anything described here.

Children

Skuvelo is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Automated decisions

Skuvelo forecasts demand and recommends reorder quantities. These are recommendations for you to act on, not decisions made about any individual, and they produce no legal or similarly significant effect on any person.

Contact us

Questions about this policy, or about the data we hold, go to our privacy address and we will answer. If you are exercising a right described above, tell us which one — it helps us respond faster.

Ventral Ventures LLC
d/b/a Skuvelo
P.O. Box XXXXX, Austin, TX 78660, United States
privacy@skuvelo.com