Legal

Privacy Policy

Last updated 28 August 202611 sections · ~6 min read

Inventory Alpha is inventory software you install on your own WordPress site, which shapes this policy: most of what the software touches never leaves your server. This policy explains the information we do hold, why we hold it, who we share it with, and what you can ask us to do with it.

Last updated
28 August 2026
01

Who we are and how to contact us

Inventory Alpha is a trading name of AJL Tech Group Limited, a company registered in England and Wales, company number 16980095. We are the data controller for the information described in this policy.

For privacy questions, data requests, and anything else, email support@inventoryalpha.com.

02

What this policy covers

This policy applies to inventoryalpha.com, your Inventory Alpha account and billing, the licence check-in the plugin makes with our servers, support conversations, the on-site chat assistant, and our affiliate programme.

It does not cover the data held inside your own store — see "Your store's data stays on your site" below.

Inventory Alpha is sold to businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.

03

Information we collect

  • Account details — your name, email address, and either a password (stored hashed) or a Google sign-in connection
  • Onboarding answers — optional questions about your business that we ask when you first sign in
  • Billing details — your name, billing address, plan, and invoice history. We never receive or store your full card number
  • Support and chat messages — what you write to us, and anything you type into the on-site chat assistant
  • Affiliate details — if you join the affiliate programme, the identity, tax, and bank details needed to pay you, which you provide directly to Stripe
  • Analytics — if, and only if, you accept analytics cookies, which pages you visit and how you arrived
  • Server logs — IP addresses, browser user-agent strings, and timestamps, so we can keep the service secure and diagnose faults

When someone follows an affiliate link, we store a one-way hash of their IP address rather than the address itself.

04

What the plugin sends us

Once a day the plugin checks in with our licensing server to confirm your licence is valid. The check-in carries your licence and site identifiers, plus a small number of setup indicators — such as whether you have raised a purchase order — so our setup emails stop once you are up and running.

It sends no page URLs, nothing about your customers, and no contents of any kind: not a product name, not a supplier, not a figure from a report. The fields are listed at /privacy/plugin-data.

05

Your store's data stays on your site

Inventory Alpha runs inside your own WordPress installation and writes to your own database. Your products, stock levels, cost prices, purchase orders, suppliers, orders, customer records, movement history, and reports are stored there and nowhere else.

We do not receive that data, we do not store it, and we have no access to it. That means we are not a processor of your customers' personal data. Where your store handles personal data about your own customers, you remain the controller of it, and your own obligations apply to it.

If your subscription ends, that data stays exactly where it is.

06

How we use your information, and our legal bases

Under UK data protection law we must have a lawful basis for everything we do with your data. Ours are:

  • Running the software and your licence — to perform our contract with you
  • Taking payment, issuing invoices, and keeping accounting records — to perform our contract, and to meet our legal obligations
  • Answering your support messages — to perform our contract with you
  • Sending service and setup emails — our legitimate interest in helping you get the product working
  • Understanding how inventoryalpha.com is used, through analytics — your consent, which you can withdraw at any time
  • Keeping the service secure, preventing abuse, and investigating faults — our legitimate interest in protecting the service and its users

We do not sell your personal data, and we do not share it with advertisers.

07

Cookies

We group cookies into three categories:

  • Strictly necessary — sign-in sessions, security, and remembering your cookie choice. These are always on, because the site cannot work without them
  • Analytics — used to understand which pages are useful. Off by default
  • Marketing — used to measure whether our advertising works. Off by default

Analytics and marketing cookies stay switched off until you turn them on. You can change your choice at any time using the cookie preferences panel on the site.

08

Who we share your information with

We use a small number of suppliers to run the service. Each receives only what it needs to do its job:

  • Hosting and infrastructure providers, including our database, application, and file storage hosts
  • Stripe — payments, subscriptions, invoices, and affiliate payouts. Your card details go directly to Stripe and are handled entirely by them
  • Email and support-desk providers, for account, billing, and support correspondence
  • Google — website analytics, used only if you accept analytics cookies
  • AI providers powering the on-site chat assistant. Whatever you type into the chat is sent to them to produce a reply, so please do not paste passwords or licence keys into it
  • Review and feedback platforms

We may also share information where the law requires it, or where it is necessary to establish or defend a legal claim. If the business is sold or transferred, your information may transfer with it.

We do not sell your personal data to anyone.

09

Where we keep it, how we protect it, and how long we hold it

Our database and sign-in system are hosted in the European Union. Several of the suppliers above are based in the United States, so some information is transferred outside the UK. Where that happens, we rely on the UK's adequacy regulations where they apply, and otherwise on the standard contractual clauses and UK International Data Transfer Addendum in our suppliers' terms.

We protect your data with encryption in transit, hashed passwords, rate limiting, and access controls limited to those who need them. No system is perfectly secure. If a breach affects your rights, we will notify you and the Information Commissioner's Office as the law requires.

We keep billing and invoice records for seven years, because tax law requires it. Everything else we keep for as long as your account is open, and for a reasonable period afterwards while we may still need it — after which we delete it or strip out anything that identifies you.

10

Your rights

Under UK data protection law you can ask us to:

  • Give you a copy of the personal data we hold about you
  • Correct anything that is wrong or incomplete
  • Delete your data, where we have no continuing reason to keep it
  • Restrict how we use it, or object to us using it
  • Send your data to you, or to another provider, in a portable format
  • Stop sending you marketing, at any time
  • Withdraw a consent you previously gave, such as for analytics cookies

Email support@inventoryalpha.com if you have any questions. There is no charge.

11

Changes to this policy

We update this policy when what we do with data changes. The date at the top of this page always reflects the current version.