Privacy Policy

Last updated: 17 August 2026

1. Data controller

The controller of your personal data is Mapka P.S.A., with its registered office in Wrocław, Hermanowska 6A, 54-314 Wrocław, entered in the register of entrepreneurs of the National Court Register under KRS number 0001196336, NIP 8943269501 — operator of the Sancho WMS product: the website, web application and mobile application.

Contact regarding data protection matters: contact@sancho-wms.pl.

2. Policy scope

This policy applies to visitors to our website, users of the Sancho WMS web and mobile application, and persons contacting us via the contact form or email.

The policy does not cover data that Customers enter into the service as part of using Sancho WMS, such as counterparty data, warehouse documents, or invoices. The Customer is the controller of this data, and Mapka P.S.A. processes it as a processor — the rules of this processing are set out in Terms and Conditions.

The policy does not apply to third-party websites linked from our site.

3. What data we collect

3.1 Website (without account)

  • technical and statistical data collected by PostHog in cookieless mode: IP address, browser type, device and operating system, visited subpages, basic events (views, clicks) and JavaScript errors;
  • contact form data: first and last name, email address, and message content; the form is protected by Cloudflare Turnstile, which for verification purposes transmits the IP address and security token to Cloudflare.

3.2 Application (registered users)

  • account data: full name, email address, password (stored only as a cryptographic hash) or identity from Google or Nextcloud sign-in;
  • billing data: company name, address, Tax ID — processed in connection with payments handled by Stripe;
  • data on the use of the web and mobile application (PostHog): product events, application lifecycle events (launch, closure, installation, update), session recordings, error reports together with stack traces, error and warning messages recorded in the application console, and network request telemetry (response times and latencies);
  • communication: content of requests, messages and feedback sent to us.

3.3 Mobile app

  • photos of delivery documents and products taken with the camera are sent to our servers, and delivery documents additionally to the OCR service;
  • barcode scanning is performed entirely on the device — the camera image is not transmitted;
  • application update requests (Expo/EAS) include device and app version metadata;
  • push notification token — if you consent to notifications, the application retrieves a token, i.e. an identifier assigned to this application installation by Firebase Cloud Messaging (Google) and Expo Push Service. This is a device identifier, although in itself it does not directly contain personal data. As part of token registration with Expo, the following are also transferred: the native FCM (Android) or APNs (iOS) token, the application installation identifier, the application package identifier, and the EAS project identifier;
  • device identifier stored on our servers — together with the push token, the application sends us the identifier assigned by the operating system (Android ID on Android, identifierForVendor on iOS). We store it in our database along with the platform, registration date, last activity date and withdrawal date. The identifier is persistent for a given application installation on a given device and allows us to link subsequent rotated push tokens to the same device. On Android, it is assigned to the combination of the application's signing key, user and device, and changes after a factory reset or a change of the signing key; on iOS, it changes after all applications from the same publisher are uninstalled.

3.4 AI Assistant

If the AI assistant feature is enabled, the chat message content is processed by Google (Gemini / Vertex AI) or Anthropic (Claude) to generate a response.

4. Purposes and legal bases for processing

  • operation and security of the website — legitimate interest (Art. 6(1)(f) GDPR);
  • account setup and management and provision of the service — performance of the contract (Article 6(1)(b) GDPR);
  • settlements and accounting — legal obligation (Art. 6(1)(c) GDPR);
  • analytics and product development — legitimate interest (Art. 6(1)(f) GDPR);
  • support and communication with users — performance of the contract and legitimate interest (Article 6(1)(b) and (f) GDPR);
  • sending push notifications about events in the system, e.g. quality control assignment, a comment on a document, or a change of document status — performance of the contract Art. 6(1)(b) GDPR and the legitimate interest consisting in informing the user about events relevant to the use of the service Art. 6(1)(f) GDPR; receiving notifications requires consent granted at the device operating system level, which you may withdraw at any time in the device settings without affecting the other functions of the application;
  • replying to messages from the contact form — legitimate interest (Art. 6(1)(f) GDPR);
  • establishment, investigation and defense of claims — legitimate interest (Article 6(1)(f) GDPR).

5. Cookies and similar technologies

On the website, the PostHog analytics tool operates in cookieless mode — it does not store cookies or data in the browser memory. For this reason, the website does not display a cookie consent banner.

The application uses its own (first-party) cookies and the browser's local storage to support login sessions and product analytics.

6. Processors

We use the following service providers who process data on our behalf:

  • PostHog Inc. — product analytics, session recordings, and error monitoring; data stored in the EU region (PostHog Cloud EU, Frankfurt);
  • Stripe — payment, subscription and invoicing support; Stripe is PCI DSS Level 1 certified, and we do not store full payment card details;
  • Fakturownia — issuing invoices and handling settlements (Customers billing data)
  • HubSpot — CRM and sales communication (customers’ contact and billing data);
  • Parser — Delivery document OCR (processing uploaded documents and the data extracted from them);
  • Cloudflare — file storage, transactional email delivery, and form protection (Turnstile);
  • Axiom — server log aggregation
  • Google (Gemini / Vertex AI) and Anthropic (Claude) — processing of AI assistant conversation content, only when the feature is enabled;
  • Expo — 650 Industries, Inc. (United States), operating under the Expo brand: delivery of mobile application updates (EAS Update) and delivery of push notifications (Expo Push Service). As part of Expo Push Service, Expo stores and processes the push token (ExponentPushToken) linked to the native FCM or APNs token, the application installation identifier, the application bundle identifier, and the EAS project identifier — solely for the purpose of directing the notification to the correct device. The content of the notification itself also passes through Expo, and then through FCM or APNs — its title and description of the event, which may include the full name of the person whose action triggered the event, and the designation of the document to which the event relates. Update requests handled by EAS Update additionally transmit device and application version metadata;
  • Google (Firebase Cloud Messaging) — delivery of push notifications to Android devices; processes the Firebase installation ID and the device registration token required to deliver the notification, as well as the content of the delivered notification to the extent described above.

We store application data on our own server infrastructure located in the European Union.

7. Data recipients

We transfer data only when necessary: to the service providers listed above, professional advisers (lawyers, accountants, auditors) bound by confidentiality obligations, and public authorities and courts when required by law. We do not sell personal data.

8. Transferring data outside the EEA

Where possible, we use suppliers that store data within the European Union, including PostHog Cloud EU. If data is transferred outside the European Economic Area, including to Stripe, HubSpot, Google, and Anthropic, the transfer is based on a European Commission adequacy decision, including the EU-U.S. Data Privacy Framework, or on standard contractual clauses (SCC).

This applies in particular to the handling of push notifications: 650 Industries, Inc. (Expo) and Google LLC are established in the United States and hold active certification under the EU-U.S. Data Privacy Framework, as well as its UK Extension and the Swiss-U.S. Data Privacy Framework. The transfer of data to these entities is based on the European Commission's adequacy decision, and to the extent not covered by this mechanism, on standard contractual clauses (SCC).

9. Data retention period

  • account data — for the duration of the agreement and for up to 30 days after account deletion;
  • accounting and bookkeeping documents — 5 years, in accordance with accounting regulations;
  • analytical data — according to the retention period configured in PostHog;
  • push notification token and the associated device identifier — we mark the device registration as withdrawn on logout and when the Expo service reports that the device is unreachable (e.g. after the app is uninstalled); withdrawing consent for notifications in the operating system settings stops them from being displayed, but does not in itself remove the registration. A withdrawn registration is no longer used for sending, while the database record itself is deleted only when the user account is deleted — we do not run a separate cleanup task for withdrawn registrations;
  • contact form messages — up to 12 months after the correspondence ends.

We retain data longer only where required by law or where necessary to establish, pursue or defend claims.

10. Your rights

Under GDPR, you have the following rights:

  • right to access your data
  • right to rectify data
  • right to delete data
  • right to restrict processing
  • right to data portability
  • right to object to processing based on legitimate interest
  • the right to withdraw consent at any time — if processing is based on it.

To exercise your rights, contact us at: contact@sancho-wms.pl. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).

11. Children's data

The service is intended for businesses and is not intended for children under 16 years of age. We do not knowingly collect children's data — if you believe that a child has provided us with their data, please contact us to have it removed.

12. Privacy policy changes

We may update this policy periodically. We publish changes on this page and update the Last updated date. We may also notify you of material changes by email or in the application.