Privacy policy

How personal data is handled.

User accounts and payment are not in operation yet. The sections about them describe what is intended — today Shopfloor Wizard runs entirely in the browser on your device.

2.1 Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Willian Vent Shopfloor Wizard Alter Postweg 37 46282 Dorsten Germany Email: support@shopfloorwizard.com

2.2 Principles of processing

Shopfloor Wizard is designed around data minimisation. Under the current technical architecture, project content such as factory layouts, material data, material flow data and the visualisations produced from them is processed locally in the user’s browser. The operator does not deliberately store this project content on its own servers and does not use it for analysis, advertising or training purposes.

Independently of that, providing an internet application involves technically necessary personal data, in particular connection and log data as well as data arising from sign-up, account management and payment. The service providers described below are used for this.

2.3 Visiting the website and hosting by Vercel

Shopfloor Wizard is delivered through services of Vercel Inc. When the website or application is called up, the following technical data in particular may be processed:

  • IP address;
  • date and time of the request;
  • the URL or resource requested and HTTP metadata;
  • browser type, operating system, device and language settings;
  • referrer information, where transmitted by the browser;
  • technical diagnostic, security, capacity and log data;
  • approximate location information derived from the IP address.

The processing serves to deliver the website, to keep the service stable and secure, to prevent misuse and to analyse technical faults. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing Shopfloor Wizard securely, reliably and efficiently.

Where Vercel processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR. Vercel may process data in the United States and other countries. For transfers to the USA, Vercel states that it relies among other things on the EU-US Data Privacy Framework and, where necessary, on further appropriate safeguards such as standard contractual clauses.

Further information: https://vercel.com/legal/privacy-notice and https://vercel.com/legal/dpa.

2.4 User account, authentication and account data via Supabase

For registration, sign-in, session management and account security we use Supabase (Supabase, Inc.). The Supabase project we use is operated in a region within the European Union. Depending on the chosen sign-in method and configuration, the following data in particular may be processed:

  • email address and other account data provided by the user;
  • access credentials in secured form, in particular a password hash;
  • internal user, session and authentication identifiers;
  • sign-in times, authentication status and security events;
  • IP address as well as browser, device and technical connection data;
  • where applicable, data from an external login provider chosen by the user or from two-factor authentication, should such methods be enabled later.

In the database belonging to Supabase we additionally store the account master data required for operation as well as the subscription status taken over from the payment service, in particular the assignment of an account to a plan, the status of the subscription and the end of its term. We do not process payment data ourselves; section 2.6 applies to that.

The processing serves to set up and manage the user account, to authenticate users, to secure the service and to provide account-related functions including access to the features booked. Where the processing is necessary for the use of an account or a booked service, it is based on Art. 6(1)(b) GDPR. Security and misuse prevention measures are additionally based on Art. 6(1)(f) GDPR.

Technically necessary cookies or token mechanisms are used for authentication in order to maintain the session of a signed-in user. Their names and exact form depend on the project, the domain and the configuration. These mechanisms are necessary for the sign-in and session management expressly requested by the user and must not be used by us for advertising or profiling.

Where Supabase processes personal data on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR. Storage takes place in the chosen EU region. Supabase, Inc. is based in the United States and may engage sub-processors, so access from third countries in the course of operation and support cannot be ruled out. For such transfers, appropriate safeguards under Art. 44 et seq. GDPR are used, in particular standard contractual clauses.

Further information: https://supabase.com/privacy and https://supabase.com/legal/dpa.

2.5 Local processing of factory layouts and project data

The core function of Shopfloor Wizard is designed so that the factory layouts, material data, material flow data and configurations selected by the user, together with the heat maps and visualisations produced from them, are processed locally in the user’s browser environment.

Under the current architecture:

  • The contents of the project files are not deliberately transmitted to the operator.
  • This project content is not stored server-side by the operator.
  • This project content is not used for advertising, user profiles or the training of models.
  • Where project states are stored locally through local storage, IndexedDB or comparable browser storage, that information stays on the user’s device or in the user’s browser profile, unless the user exports or otherwise transmits it.

Where storing information on, or accessing information in, the device is strictly necessary to provide a function expressly requested by the user, this takes place under § 25(2) no. 2 TDDDG without separate consent. Storage for tracking or marketing that is not technically necessary is not currently intended.

Important: if the user clears browser data, changes device or browser profile, or a browser or company policy blocks local storage, locally stored project states may be lost. As we do not secure this project content server-side, we generally cannot restore it.

2.6 Payments and subscriptions via Lemon Squeezy

For paid plans we use Lemon Squeezy / Sold through Link, LLC as merchant of record or authorised reseller. The payment process is handled by Lemon Squeezy. Lemon Squeezy processes the data required for the transaction, in particular contact, invoicing, payment, tax, transaction and fraud prevention data, under the terms and privacy notices applicable there.

Lemon Squeezy may transmit to us the information required to activate and manage a purchased access, for example the product or plan, the subscription status, a transaction or subscription identifier and — depending on the concrete integration — an assignment to the user account. We process such data only to the extent necessary to provide, manage and bill the access booked or to handle contract-related enquiries.

The legal basis is Art. 6(1)(b) GDPR where the data is necessary to perform the contract or to provide the access booked. Retention required by law may additionally be based on Art. 6(1)(c) GDPR.

Lemon Squeezy is a US provider. Further information: https://www.lemonsqueezy.com/privacy, https://www.lemonsqueezy.com/dpa and https://www.lemonsqueezy.com/buyer-terms.

2.7 Contact and support

If you contact us by email or through a support channel provided in future, we process the data you send, in particular contact details and message content, in order to deal with your request.

The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or to pre-contractual measures, otherwise Art. 6(1)(f) GDPR. Our legitimate interest lies in dealing properly with enquiries, support and security reports.

Please do not send confidential factory, operational or project data through general support channels unless it is necessary in order to deal with the matter.

2.8 Cookies, local storage and similar technologies

We currently use no analytics, advertising or marketing cookies of our own. Technically necessary cookies and storage mechanisms may however be used, in particular:

  • by Supabase for authentication and session management;
  • by Shopfloor Wizard for local project or configuration functions expressly requested by the user;
  • on external pages of payment or authentication providers, under their own responsibility and configuration.

Where access to storage is strictly necessary for the digital service expressly requested, no consent is required under § 25(2) no. 2 TDDDG. Should analytics, marketing or tracking technologies that are not necessary be used in future, we will amend this privacy policy and — where required — obtain valid consent before they are activated.

2.9 No web analytics and no profiling by us

As things currently stand we use no web analytics, heat map, advertising or cross-site tracking services for visitor behaviour. In particular, no profiling of users for marketing purposes is currently intended.

Note: this statement holds only as long as functions such as Vercel Analytics, Vercel Speed Insights or other analytics and monitoring services are not activated.

2.10 Recipients and processors

Personal data may be transmitted — in each case only to the extent necessary — to the following categories of recipients in particular:

  • hosting and infrastructure providers (currently Vercel);
  • authentication, database and user management providers (currently Supabase);
  • payment and reseller providers (currently Lemon Squeezy);
  • technical, legal or official recipients where this is necessary to meet legal obligations or to enforce rights.

Any transfer beyond this for advertising purposes is not currently intended.

2.11 Transfers to third countries

Some of our service providers are based in the United States or use sub-processors outside the European Economic Area. Where personal data is transferred to third countries, this takes place only in compliance with Art. 44 et seq. GDPR. Depending on the provider and the processing, adequacy decisions, in particular the EU-US Data Privacy Framework, standard contractual clauses or other appropriate safeguards may be relied upon.

2.12 Retention

We store personal data only for as long as this is necessary for the respective purpose or as long as statutory retention obligations exist.

  • Project content processed exclusively locally in the browser is not stored by us server-side.
  • Account data is generally processed for the duration of the user account and afterwards only for as long as this is necessary for settlement, security, legal defence or statutory obligations.
  • Contract and billing data may be kept longer in line with commercial and tax retention obligations.
  • Technical log data is kept, according to the security and retention settings of the infrastructure used, only for as long as this is necessary for operation, security and the prevention of misuse.

Specific retention periods may follow from the settings and terms of the respective service providers.

2.13 Legal bases at a glance

Depending on the processing, we rely in particular on:

  • Art. 6(1)(b) GDPR for the performance of a contract and pre-contractual measures;
  • Art. 6(1)(c) GDPR for legal obligations;
  • Art. 6(1)(f) GDPR for legitimate interests such as secure provision, prevention of misuse, support and legal defence;
  • Art. 6(1)(a) GDPR only where we expressly obtain consent for a particular processing.

2.14 Rights of data subjects

Where the statutory conditions are met, you have in particular the right to:

  • access under Art. 15 GDPR;
  • rectification under Art. 16 GDPR;
  • erasure under Art. 17 GDPR;
  • restriction of processing under Art. 18 GDPR;
  • data portability under Art. 20 GDPR;
  • object to processing based on Art. 6(1)(e) or (f) GDPR under Art. 21 GDPR;
  • withdraw consent given, with effect for the future.

A message to support@shopfloorwizard.com is enough to exercise your rights. We may ask for reasonable proof of identity where this is necessary to protect your data against unauthorised access.

2.15 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. For a controller based in Dorsten, the competent authority is usually the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW):

Kavalleriestraße 2-4 40213 Düsseldorf Germany https://www.ldi.nrw.de/

You may also contact any other supervisory authority competent under Art. 77 GDPR.

2.16 Automated decisions

As things currently stand we take no decisions based solely on automated processing that produce legal effects or similarly significantly affect data subjects within the meaning of Art. 22 GDPR, and we carry out no marketing profiling.

2.17 Changes to this privacy policy

We amend this privacy policy when the functions of Shopfloor Wizard, the service providers used or the legal requirements change. The version in force at the time is published on the website.

Last updated: 1 September 2026