Legal

Privacy Policy

Last updated: September 10, 2026

1. Who we are and our role

Storely is operated by High Ground Software LLC, a California limited liability company ("HGS," "we," or "us"). This policy describes information handled through our website, application, and support services.

For account administration, subscription billing, support, and service security, we determine how information is used for those purposes. For operational information submitted by a 3PL customer ("Customer"), its users, or its connected services ("Customer Data"), we process information on the Customer's behalf to provide the Service. The Customer may itself be acting on behalf of its clients. The relevant Customer's or client's privacy notice explains its own uses of that information.

Warehouse staff and invited client users can both have accounts. Invited client users access information within permissions administered by the Customer. This policy does not transfer control of warehouse records to individual users or replace an applicable data-processing agreement.

2. Information we handle

Account and contact information includes names, work email addresses, company details, phone numbers where provided, user roles, authentication information, and records of account and agreement activity.

Customer Data includes client and product details, inventory, work orders, shipments, shipping names and addresses, contact details, invoices, and related activity records. Customers may attach documents, product images, labels, and other files, which can also contain personal information. Information may be entered directly, supplied by invited client users, or imported from integrations the Customer enables.

Subscription payments are processed through Stripe. HGS does not store full payment-card numbers. We receive information needed to administer payments, such as billing contact details, payment status, and limited payment-method information. Warehouse invoices and charges recorded in Storely are separate from HGS subscription payments.

Support information includes messages and any records or attachments you provide to help investigate an issue. Technical and security information can include IP addresses, browser/device information, timestamps, errors, and account or application activity.

Barcode scanning is used to look up or log items; scanned images are not retained as attachments automatically. Images deliberately uploaded as attachments are stored. Do not submit patient records, identity documents, full payment or banking credentials, or other unsupported sensitive records.

3. Cookies, local storage and external resources

The application uses authentication-related technologies to maintain sessions. Our website stores your light/dark theme preference in your browser's local storage. Browser settings let you remove or restrict cookies and local storage, although restricting authentication storage may prevent login.

Our website loads fonts from Google Fonts. This causes your browser to contact Google and transmit technical request information, such as your IP address and browser information. This external font request is distinct from advertising tracking.

We do not use third-party advertising trackers or session-replay tools and do not sell or share personal information for cross-context behavioral advertising. We do not track your activity across unrelated websites for advertising. Legacy browser Do Not Track signals do not change these practices. We respect applicable opt-out requirements, including qualifying browser privacy signals where relevant.

4. How we use information

We use account, billing, support, and technical information to provide and administer Storely, authenticate users, process subscriptions, respond to questions, investigate errors, prevent abuse, send operational notices, and comply with legal obligations or establish and defend legal claims.

We process Customer Data to provide the warehouse functions requested by the Customer, maintain security, support authorized users, and follow lawful instructions. We do not use it for AI model training, cross-customer benchmarks, or advertising to clients or shipment recipients.

We do not currently operate a marketing mailing program. If we introduce marketing communications, we will provide the notices, choices, and consent mechanisms required by applicable law. Operational and security messages are separate from marketing.

5. Who receives information

Authorized Customer administrators and users can access information within their assigned roles. The Customer manages its client users' access, and warehouse administrators can access the records needed to administer their tenant.

We use Microsoft Azure services for application hosting, databases, attachment storage, operational email through Azure Communication Services, and monitoring. These providers process information to support the Service under applicable contractual arrangements. Stripe processes subscription payments and may also handle information for its own compliance, fraud-prevention, and other purposes described in its privacy notice.

If the Customer enables an available integration, we exchange the information needed for the authorized functionality with that provider. Planned connections include Shopify, Amazon, Walmart, eBay, and QuickBooks Online; listing them here does not mean they are currently available or receive information from your account. A provider's own terms and privacy notice govern its independent processing. Disconnecting a connection does not automatically erase information already transferred.

We may disclose information where legally required or reasonably necessary to investigate abuse, protect rights or safety, or establish or defend legal claims, subject to applicable restrictions on Customer Data. In a merger, acquisition, or asset transfer, information may be transferred subject to applicable law and continuing privacy obligations.

We do not sell personal information or share it for cross-context behavioral advertising. External website font requests are described above.

6. Retention, exports and deletion

We retain information for the purposes described in this policy, considering whether an account is active, the information's operational purpose, legal recordkeeping requirements, security needs, and unresolved claims. Different records may have different retention periods.

Customers have a 30-day window after trial expiry or subscription termination to request an export. Verified Customer administrators can request secure manual assistance even when login is blocked. Exports include Customer operational records in machine-readable formats, such as JSON or CSV, and uploaded attachment files with information needed to associate them with their records. Attachments may be delivered separately.

We provide advance notice before routine deletion and do not routinely delete Customer Data during that window or while a timely export request remains unfulfilled. Afterward, we delete operational records and attachments from active systems through our managed deletion process. Backup copies can remain until their applicable retention cycles expire and are then deleted or overwritten, rather than disappearing immediately when a database is deleted. Retained backup data is restricted to recovery, security, and legal purposes.

Account, billing, security, and dispute records may be retained separately where needed for those purposes or required by law. We remove temporary export copies when no longer needed for delivery and related support. Contact us for information about retention applicable to your account or a deletion request; applicable legal requirements and agreed processing terms take precedence.

7. Security and access

Each 3PL customer has a dedicated database for its warehouse operational records, separate from the databases used by other 3PL customers. Uploaded attachments are stored separately with access controls. Account administration and underlying service infrastructure may be shared; dedicated databases do not mean dedicated physical infrastructure.

Our safeguards include encryption in transit and at rest, role-based access controls, multi-factor authentication for privileged HGS access, access logging, backup and restoration procedures, and an incident-response process. HGS personnel access Customer Data only when needed to operate, support, or secure the Service or comply with law. We restrict and log that access. We assess suspected incidents and notify affected Customers and others as required by applicable law and our agreements. No online service can guarantee absolute security. Contact [email protected] promptly if you suspect an information-security issue.

8. Privacy rights and requests

Depending on applicable law, you may have rights to access or obtain a copy of personal information, correct inaccurate information, request deletion, object to or restrict processing, withdraw consent where processing relies on consent, or make a complaint to a privacy regulator. Rights are subject to applicable conditions and exceptions.

Email [email protected] or write to the address below. Describe your relationship to Storely and the request without including passwords or unnecessary sensitive documents. We may verify your identity and authority before acting, and will respond within applicable legal time limits. Authorized representatives may submit requests with evidence of their authority. We will explain any lawful refusal and available review or complaint options.

For operational records held on behalf of a Customer or its client, contact the warehouse or relevant business responsible for that information. If you contact HGS, we will help route the request and assist the Customer as required. An individual account-deletion request does not automatically authorize deletion of an entire tenant's business records.

California residents may have rights under the CCPA, as amended, including rights to know/access, correct, delete, and opt out of sale or sharing, and to exercise applicable rights without unlawful discrimination. Applicability depends on the law's criteria, not simply HGS's California location. We do not sell or share personal information for cross-context behavioral advertising and do not use unsupported sensitive information for unrelated purposes.

Australian users may contact us about access, correction, or a privacy complaint. We will investigate and respond, and you may contact the Office of the Australian Information Commissioner where applicable. Nothing in this policy restricts statutory rights or complaints to other competent regulators.

9. International processing

Our service hosting and storage are in the United States. Information from users and businesses in other countries is transferred to and processed in the United States, where privacy laws may differ. Provider support and independent processing may be governed by their own arrangements and notices.

Where applicable law requires additional processing terms or safeguards for an international transfer, those arrangements must be established before the relevant processing begins. Contact [email protected] before submitting information subject to such requirements. Use of Storely alone is not treated as consent to waive privacy rights or as a substitute for a legally required transfer mechanism.

10. Children and unsupported information

Storely accounts are intended for adult business users, not children. We do not knowingly solicit accounts from children under 18. Customer-supplied shipment records may concern recipients of different ages; those records are processed on the Customer's behalf rather than as children's accounts. Contact us if you believe a child has directly provided account information or unsupported sensitive information has been submitted.

11. Policy changes

We will update this policy when our practices change. For material changes, we will notify active Customers by email or in-app notice before they take effect, and provide other notice or obtain consent where required by law. We will not treat a policy update as permission for an incompatible new use of previously collected information. The date above identifies this version.

12. Contact

High Ground Software LLC
2108 N St Ste N
Sacramento, CA 95816, USA

Privacy questions and requests: [email protected]
Support and export assistance: [email protected]