Kobo Warehouse

Privacy Policy

Version 1.0.0 · Effective 2026-08-10

Kobo Warehouse operates Kobo Warehouse, an application used by branch and warehouse staff to raise stock requests, dispatch and receive deliveries, and keep count of stock. This policy explains what the application records about the people who use it.

This is a workplace application. Accounts are created by your employer's administrator — there is no public sign-up — and the organisation that issued your account is the party responsible for the data in it. Kobo Warehouse processes that data on their behalf.

Who to contact

Questions about this policy, or about the data held about you, go to your administrator. If your organisation has its own data protection contact, ask them first — they control the account.

What is collected

Account details. Your name, email address, and optionally a username, phone number and avatar image. These are entered by your administrator when the account is created, and you can correct them yourself in the application's settings.

Where you work. Which stores, branches or warehouses you have access to, and what you are allowed to do at each — raise requests, approve them, dispatch, receive, or view only.

What you do in the application. Stock requests you raise, approve, reject or cancel; shipments you dispatch or receive; stock adjustments and counts you record; comments you leave; and alerts you acknowledge. Each of these is stored against your account, with a timestamp, because a stock ledger that cannot say who moved what is not a stock ledger.

Photographs you choose to attach. The application can attach a photo to a wastage record or a delivery discrepancy. Photos are only captured when you take them, and they are stored with the record they belong to.

Barcode scans. The camera is used to read barcodes. Images from the scanner are processed on the device and are not uploaded or stored.

Technical information. The application server records the usual request logs — time, endpoint, response status and network address — to keep the service working and to investigate faults.

What is not collected

The application does not track your location. It does not read your contacts, calendar, photo library, messages or call history. It contains no advertising and no third-party analytics or tracking software. Your data is never sold, and it is never shared for anyone else's marketing.

Why it is used

Your data is used to run the service and for nothing else:

There is no automated decision-making that produces legal or similarly significant effects.

Who it is shared with

Your organisation. Administrators and managers within your organisation can see your account details and your activity in the stores you share with them. This is the point of the application.

Service providers. The application runs on hosted infrastructure and uses third parties for the database, file storage and email delivery. They process data only to provide those services and are bound by contract.

Where the law requires it. Data may be disclosed if required by law or to protect the rights and safety of users.

How long it is kept

Account details are kept for as long as the account exists. Stock records — requests, shipments, adjustments and the movement ledger — are business records and are kept according to your organisation's retention policy and the accounting and food-safety law that applies to them, which is usually several years. These records outlive your account: after your account is erased they remain, but they no longer identify you.

Request logs are kept for a short operational period and then discarded.

Your rights

Depending on where you live, you may have the right to see the data held about you, correct it, have it erased, restrict or object to its processing, and receive a copy in a portable form. You can correct most of your own details in the application's settings. For anything else, contact your administrator or your administrator.

Deleting your account

You can request deletion from inside the application — Settings → Account → Delete my account — or from the web page at http://localhost:4000/account-deletion without installing anything.

Here is exactly what happens:

Your administrator may refuse a deletion request for an account that is shared or still operationally required. If that happens you will be told, and the account is reactivated.

Security

Passwords are stored hashed, never in readable form. Sign-in tokens on your device are held in the platform's secure keystore — Keychain on iOS, the encrypted preference store on Android — not in ordinary application storage. Traffic between the application and the server is encrypted in transit.

No system is perfectly secure. If you believe your account has been accessed by someone else, change your password in the application's settings and tell your administrator.

Children

This is a workplace application and is not directed at children. Accounts are not knowingly issued to anyone under 16.

Changes to this policy

If this policy changes materially, the version and effective date at the top of this page change with it, and the application shows the updated policy the next time you open the legal section.

Version 1.0.0 · Effective 2026-08-10