Privacy Policy
Last updated:
Overview
We collect the minimum personal information needed to deliver a reliable EDI service, support your team, and comply with legal requirements. We do not sell personal information.
Data we collect
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Account | Name, work email, password (hashed), company, role, phone (optional) | You | Account creation, login, service access, support |
| Billing | Billing contact, plan, invoice history. Card details are processed by Stripe/PayPal | You / Processor | Subscription management, fraud prevention, accounting |
| Service | Retailer selections, configuration, logs (timestamps, IP, status), document metadata (filenames, counts, sizes) | Automatic | Deliver and monitor EDI transmissions, reliability, troubleshooting |
| Diagnostics | Error traces, performance metrics, uptime pings | Automatic | Maintain and improve stability & security |
| Marketing (limited) | Page views, UTM parameters (if present) | Cookies/analytics (see below) | Understand product usage and improve onboarding |
Why we collect it (legal basis)
- Contract: to provide the service you signed up for (account, transmissions, support).
- Legitimate interests: to secure, maintain, and improve the platform; prevent abuse.
- Legal obligations: tax, accounting, fraud prevention, compliance requests.
- Consent: optional analytics or marketing emails (you can withdraw any time).
Payments
We use Stripe and/or PayPal for payment processing. Your full card data is sent directly to the processor; we don’t store it on our servers. We store billing metadata such as plan, last 4 digits, and invoice status for your records.
Email & communications
We send transactional emails (sign-in, receipts, alerts) and, if you opt in, product updates. Every non-transactional email includes an unsubscribe link. Support requests are retained for auditing and training.
Data retention
- Account & billing: kept while you’re a customer, then typically up to 24 months for records and legal obligations.
- Service logs: typically 90–180 days, unless needed to investigate abuse or incidents.
- Backups: rolling backups up to 30 days.
Security
- Encryption in transit (HTTPS) and at rest where supported by infrastructure.
- Strict access control, principle of least privilege, and audit trails for production access.
- Hashed passwords using PHP’s
password_hash(); no plaintext credentials. - Regular updates, dependency review, and monitoring.
International transfers
Processing occurs primarily in the United States. If data is transferred internationally by our subprocessors, we rely on appropriate safeguards (e.g., SCCs) provided by those vendors.
Your privacy rights
GDPR (where applicable): access, rectification, deletion, restriction, portability, and objection to processing based on legitimate interests. CCPA/CPRA (California): right to know, delete, correct, and opt-out of “sale/share” of personal information (we do not sell personal information).
To exercise rights, email us at privacy@beedi.io. We may need to verify your identity.
Children’s privacy
Our services are intended for business users. We do not knowingly collect personal information from children under 18 (or the relevant age in your jurisdiction).
Changes to this policy
We’ll post updates here and adjust the “Last updated” date. For material changes, we may notify you by email or in-app.