Truestone Software Truestone Software

Privacy Notice

Last updated: 24 July 2026

This notice explains how Truestone Software Ltd uses personal data through our websites, enquiries, business relationships, software services and authorised marketplace integrations, including TrueSKU.

1. Who we are

Truestone Software Ltd is a company registered in England and Wales under company number 16318064. Our registered office is Rutherford House, The Drove, Blackfield, Southampton, England, SO45 1XB.

For data-protection enquiries or to exercise your rights, email info@truestonesoftware.com. We have not appointed a statutory Data Protection Officer; responsibility for privacy is held by the company director.

2. Our role

We are normally a controller for website enquiries, account administration, billing, security and our own business records. When a customer connects a sales channel to our software, we normally act as that customer's processor for buyer, recipient, order and fulfilment data, while the customer remains the controller. The relevant platform may also be an independent controller.

3. Personal data we process

  • Enquiry and business-contact data: name, organisation, email address, message, correspondence and meeting notes.
  • Account data: user name, email address, organisation, role, authentication and security records, preferences and support history.
  • Billing data: plan, subscription status, transaction references and accounting records. Payment-card details are handled by our payment provider and are not stored by us.
  • Marketplace and commerce data: shop identifiers, products, listings, SKUs, inventory, orders, fulfilment status and, where required to provide the service, buyer or recipient name, delivery address, contact details and order messages.
  • Technical and security data: IP address, browser or device information, timestamps, audit events, diagnostic logs, authentication events and API activity.

We do not intentionally collect special-category personal data through our websites or standard software features. Customers should not enter such data unless it is necessary, lawful and agreed with us.

4. Why we use data and our lawful bases

  • To answer enquiries and take steps requested before a contract: contract or legitimate interests.
  • To provide, support and administer our software and integrations: contract; where we act as processor, on the customer's documented instructions.
  • To manage billing, tax and company records: contract and legal obligation.
  • To secure, monitor, troubleshoot and improve our services: legitimate interests in operating reliable and secure software.
  • To send requested or permitted service and business communications: contract, legitimate interests or consent where consent is required. You can opt out of marketing at any time.
  • To establish, exercise or defend legal claims and prevent misuse: legitimate interests and legal obligation where applicable.

Where we rely on legitimate interests, we consider the necessity and impact of the processing and do not use that basis where your interests or fundamental rights override ours.

5. Marketplace integrations

A seller must authorise an integration before we access its marketplace account. We request only permissions needed for the enabled features. For TrueSKU, this may include shop, product, listing, inventory, order and fulfilment data. We use that data only to provide inventory control, order ingestion, stock allocation, synchronisation, reconciliation, support and related features selected by the seller.

We do not sell marketplace data, use it for behavioural advertising, or disclose it for an unrelated purpose. Access tokens and platform credentials are treated as confidential. When a shop disconnects or the service ends, we delete or anonymise protected marketplace data in accordance with platform requirements, the customer's instructions, our retention policy and applicable law. Limited records may be retained where legally required or necessary to resolve security, billing or legal matters.

6. Sharing and service providers

We disclose personal data only where needed to operate the business or service, including to hosting and infrastructure providers, payment processors, email and support providers, professional advisers and the marketplaces or commerce platforms a customer chooses to connect. We may also disclose data where required by law, to protect rights or security, or as part of a corporate transaction subject to appropriate safeguards.

Our principal production systems are hosted in the United Kingdom. Some suppliers may process limited data in the UK, European Economic Area or other countries. Where restricted transfers occur, we use an applicable safeguard such as an adequacy regulation or approved contractual clauses, together with supplementary measures where appropriate.

7. Retention

  • Enquiries that do not become a customer relationship: normally up to 24 months after the last meaningful contact.
  • Customer account and service records: for the relationship and normally up to 24 months afterwards, except where a longer period is required for a stated purpose.
  • Marketplace buyer, recipient, order and fulfilment data: only for as long as needed to provide the enabled service, meet platform rules and handle support, disputes or legal obligations; disconnected-shop data is scheduled for deletion or anonymisation.
  • Security and operational logs: normally 30 to 365 days according to log type and risk.
  • Invoices, payments and records needed for tax or accounting: normally six years after the relevant financial year.

Backups expire on a rolling schedule. Data deleted from live systems may remain inaccessible in encrypted backups until the relevant backup expires, unless restoration is required for disaster recovery.

8. Security

We use proportionate technical and organisational safeguards including access control and least privilege, multi-factor authentication for privileged and business-critical access, encryption in transit, protected credentials, network restrictions, private database networking, endpoint protection, logging, backups, vulnerability management and incident-response procedures. No internet service can guarantee absolute security.

9. Cookies

Our public website may use cookies or similar storage that are strictly necessary for security, forms, sessions or requested functionality. If we introduce non-essential analytics or advertising technologies, we will provide appropriate information and obtain consent where required.

10. Your rights

Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data; object to processing; receive portable data; and withdraw consent without affecting earlier lawful processing. You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint/.

If your request concerns data held for one of our business customers, we may refer the request to that customer and assist them as their processor. We may need to verify identity and may retain a record of the request and response.

11. Changes

We may update this notice when our services, suppliers or legal obligations change. We will publish the revised date and, where appropriate, provide additional notice of a material change.