Nabel Solutions

Legal

Privacy notice

Short for the website, which collects almost nothing. Longer for the products, because they differ.

In effect from 29 August 2026

This website

This site sets no cookies. It runs no analytics, no advertising pixels and no third-party tracking of any kind. It loads no fonts, scripts, images or embeds from other domains, so visiting a page here does not disclose your visit to anyone else.

Our hosting provider processes standard server request data — including your IP address — in order to serve the page and to protect the site from abuse. That is a technical necessity of the web rather than a choice we have made to collect information about you.

If you contact us

There is no form on this site. Every "get in touch" link opens a message in your own email program, addressed to us. Nothing is collected by this website — you send us an email, and we receive it.

That means we hold whatever you chose to put in it: your name, your email address, and anything you wrote. Our email provider processes it in order to deliver it, as it would any other message. We use it to answer you and, if it leads somewhere, to carry on that conversation.

Enquiries stay in that mailbox. They are not copied into a CRM, a spreadsheet, a mailing platform or an advertising network, and we do not sell or share them.

Alongside replying, we may occasionally write to you about the product — a release, or something we think is relevant to your operation. Tell us to stop and we will, and every such message will say how.

Retention

We keep enquiries for two years after we last hear from you, then delete them. Ask us to delete yours sooner and we will.

Your rights

You can ask what we hold about you, ask us to correct it, or ask us to delete it. Write to [email protected] and we will respond.

Serial Xtractor products

How a deployment handles data depends on which deployment it is, and the difference is large enough to state plainly rather than in general terms.

The offline deployments — the secure tablet, the fixed mount and the on-shredder unit — operate with no connectivity. They transmit nothing to us, we have no access to the records they produce, and what a unit captures stays on that unit until your operator exports it.

The mobile app is a connected product. Scanning works without a connection, but the app is backed by a cloud service we operate, and exporting a manifest or a set of results requires connectivity.

What the app collects. Set out by category, in the terms the app stores use:

Contact information — your email address.

User content — photographs taken while scanning, and the serial numbers read from them. Anything else visible on a label in shot is captured with it.

Identifiers — your user ID, your organization ID, a device attestation token, and your IP address.

Usage data — which parts of the product you use, and session events.

Diagnostics — crash logs and performance data.

Who processes it. We use these companies to run the service. Each receives only what its job needs:

Supabase (a Delaware corporation, hosted on AWS in US-East-2) — sign-in, database and file storage. Your sessions, images and serials are held here. PostHog — product analytics. Sentry — crash reporting. Resend — the emails the service sends you. Stripe — billing. This is at the organization level rather than in the app itself, and card details go to Stripe rather than to us.

How long we keep it. Sessions, images and serial numbers are kept for the life of your organization's account, and deleted within 30 days of the account being deleted — or sooner if you ask for a specific record to go. Diagnostic and analytics data is kept for 90 days and then reduced to aggregate counts that identify nobody. Images marked as excluded from training are removed from our training set within 24 hours.

How to withdraw. Delete your account from the app: Settings, then Account, then Delete account. Everything tied to your organization is removed within 30 days. You can also write to [email protected] and we will do it for you. See account deletion for what is removed and what is not.

Detecting abuse of the free tier. We process a device attestation token, your IP address, and cryptographic hashes of images and payment details to spot one person opening many accounts. Those hashes cannot be reversed to identify anyone, and are used for nothing else.

This cannot currently be switched off in the app. If your operation cannot place that data with a third party, use one of the offline deployments — that is precisely what they are for.

Deployment agreements cover product data handling in full, and we will answer a security questionnaire in writing.

Changes

We will update this page if what we do changes. It carries no version history yet because it has not changed.