A steel cabinet standing closed in an empty room at night, one light raking across it

what happens to your data

Privacy policy.

Your data is yours. This is the whole of what we hold, where it sits, who else can touch it and how to have it gone.

Last updated 5 September 2026
12 numbered clauses
  1. 1

    Who holds your data

    The registered company that operates Panlytics. Its full legal name, company number and registered address are set out in the agreement you sign, and we will send them to anyone who asks.

    To ask anything about your data, or to have it deleted, email aayan@panlytics.net or ari@panlytics.net.

  2. 2

    What we handle

    Your sales data, and any personal details that appear inside it, such as the names or contact details of your staff or your customers. The people whose data this is are your employees and users, and anyone appearing in the sales data you give us access to.

    No sensitive personal data, unless we have agreed it in writing first. Please do not upload sensitive personal information, such as health data, without agreeing it with us first.

  3. 3

    Why we handle it

    To run Panlytics for you, and to test and improve it. We handle your data on your behalf when we run the service, and for our own purposes when we use it to improve Panlytics.

    You confirm you may share it with us for that purpose and have told anyone whose personal details appear in it.

  4. 4

    How long we keep it

    While your agreement runs, and after it ends until you email us to delete it. When you do, we stop using it straight away, delete it from our systems within 30 days, tell our hosting provider to do the same, and confirm when it is done.

    We may keep fully anonymous combined statistics, which cannot identify you or any person, and anything the law requires. Every two years we review what we hold and delete what we no longer need.

  5. 5

    Where it is kept

    Amsterdam, in the Netherlands. One city, not a vague somewhere in the EU. The application, the database holding your sales figures and the store holding the original files you upload all run in Railway's EU West region. We will not move any of it elsewhere without telling you first and putting proper protections in place.

    Two things leave those servers, and we would rather list them than bury them. Usage analytics go to PostHog's EU cloud in Frankfurt, Germany; that stream is counts of what was used, not your sales file. Questions you ask Panpilot, the work the agents do for you, and the figures needed for both go to Google's Vertex AI in the Netherlands, its europe-west4 region. That is still the EU, though not Amsterdam.

    One switch can take a shop's own agent runs outside the EU, and it is off unless you turn it on. In the agent settings a shop can choose Google's global endpoint, which offers newer models and routes each call to wherever Google has capacity, including outside the EU. It applies only to that shop's agent runs; Panpilot, the store research, analytics and everything stored stay where they are.

    A third thing leaves only for shops. When we place a shop on a map we ask OpenStreetMap where its address is. That is the address of a business, not of a person, and you can switch it off for any location. Mark a place as closed to the public, such as a warehouse or a stockroom, and its address is never sent anywhere.

  6. 6

    Who else touches it

    Three outside services handle data for us. A fourth, OpenStreetMap, is listed with them because it receives something from us, though nothing about a person.

    • (a)Railway (railway.com) hosts the product and stores your data for us, in Amsterdam. That is the application, the database and the bucket holding your uploaded files. All three sit in its EU West region.
    • (b)PostHog (posthog.com) processes usage analytics for us, in its EU cloud in Frankfurt, Germany. It receives counts of pages, clicks, speeds and errors. It does not receive your sales file, and it does not record your screen.
    • (c)Google Cloud (Vertex AI) generates Panpilot's answers, the store research and the agents' work, in Google's Dutch region (europe-west4), unless a shop has switched its own agents to the global endpoint as described above. Google is a processor under its Cloud Data Processing Addendum, which is part of our agreement with them, and is contractually barred from using our customers' data to train or tune its models. If its automated abuse checks flag a request, Google may keep that request for up to 90 days. Google publishes its own providers at cloud.google.com/terms/subprocessors.
    • (d)The OpenStreetMap Foundation turns a shop's address into map coordinates. What we send is the shop's name, street, town and country: the address of a retail premises, the same words written on its front door, printed on its receipts and already drawn on every public map. That is information about a business, not about a human being, so the Foundation is not processing your personal data and is not our processor. It does log the lookup and our own server's address under its own privacy policy, and it may study such queries to improve the map. Two things are worth knowing anyway. A location you mark as closed to the public is never looked up at all, neither the address nor the name, and marking an existing one closed deletes the pin we already held. And if a business trades from somebody's home, its address is a person's address as well; tell us, or mark it closed to the public, and it stays here.
  7. 7

    Adding or changing a provider

    We will tell you 30 days before we add or replace any of them, and you can object for good reason. We have deliberately stopped claiming this list is complete for all time: it is complete as of the date at the top of this page, and the notice above is the promise that matters.

  8. 8

    Security

    Encrypted when sent and when stored. Access only through named accounts belonging to us; only our own people who need access have it, and everyone is bound to keep it confidential. Passwords are stored so that nobody, including us, can read them, and a password we set for you has to be replaced the first time you sign in.

    Two things we do not yet have, said plainly rather than left to be assumed: there is no second factor on our administrator sign-in, and we do not keep an audit log of what our own staff looked at. Both are on the list to build, and this page will say so when they exist.

    We do not currently keep separate backups of your data. Please keep your own copy of anything you cannot afford to lose. We will tell you if this changes.

  9. 9

    Analytics, exactly

    We use PostHog to see which parts of Panlytics people actually use and where it confuses them. Here is exactly what that means.

    The events we collect are page views, sign-in identification, uncaught errors, rage clicks and page-speed measurements. Each one carries the usual technical context. That means your browser, operating system, screen size, referring page, approximate location from your IP address, and a random identifier for the browser.

    When you are signed in we attach your account number and whether the account is staff or a shop manager. We do not attach your username or your name.

    • (a)We do not record your screen. No video of your session is made or stored.
    • (b)It never captures your password. Payment details are never entered into Panlytics at all.
    • (c)Nothing is collected until you accept. Analytics start switched off. Decline on the banner and we collect nothing at all.
    • (d)Your choice lives in your browser under panlytics_cookie_choice. Clear it and reload to change your mind.
    • (e)Signing in sets a panlytics_session cookie. That one is not analytics. It is what keeps you signed in, and the product cannot work without it.
  10. 10

    What we will never do

    Whatever else changes, these do not:

    • (a)we will never sell, rent, licence or publish your data;
    • (b)we will never give it to anyone outside our own team, except the providers named above;
    • (c)we will not use it to produce anything for another customer that identifies you; and
    • (d)we will not use it for anything other than running and improving Panlytics, unless the law requires it.
  11. 11

    If something goes wrong

    We will tell you within 48 hours of finding out, with what we know at the time, and help you with anything you have to report.

  12. 12

    Your rights, and checking on us

    We will help you answer any request from a person about their own data, and give you whatever you need to show that your data is being handled properly.

    You can ask us to show how we handle your data once a year, or sooner if something has gone wrong.

    If you want to complain to a regulator, the Information Commissioner's Office in the United Kingdom is the one to approach.

The commercial side of the relationship is in the terms of service. If you want your data deleted, one email is enough.