Legal
Privacy Policy
Effective September 30, 2026
What WarehouseSOP collects, why, and who else touches it. We collect what the product needs to work, we never sell it, and there are no advertising trackers on this site.
- 01
Scope
WarehouseSOP is operated by Sales Xceleration Strategies LLC, a Colorado limited liability company, and that company is the controller of the personal information described here. You can reach us about anything on this page at support@warehousesop.com.
This policy covers the WarehouseSOP marketing site at warehousesop.com and the WarehouseSOP application. It explains what we collect, why we collect it, who processes it on our behalf, and how to get it deleted. We have tried to write it in plain language, because a policy nobody can read is not really a disclosure.
The short version: we collect what the product needs to work and nothing else, we never sell personal information, and there are no advertising trackers on this site.
- 02
Information we collect
We collect the following categories of information.
- Waitlist and sample downloads. If you join the waitlist or download a sample document, we collect your email address, and your name and company if you choose to give them. That is all a download requires.
- Account data. If you use the product, we collect your name, email address, and the organization and facility profile you build during onboarding: facility type, size, equipment, shift structure, job titles, and similar operational details used to customize your SOPs.
- SOP content. The documents you generate, edit, and store in the product, including sign-off records and any notes you attach to them.
- Payment data. Subscriptions are processed by Stripe. Stripe collects and stores your card details directly. We never see or store card numbers. We receive a customer identifier, the plan you are on, the billing status, and the last four digits and card brand for your reference.
- Server logs. Standard technical records generated when you use the Site or the product: IP address, browser and device type, pages or endpoints requested, timestamps, and error traces. These are used for security, abuse prevention, and debugging.
- 03
How we use information
We use the information above to provide and operate the Service: authenticating you, generating and storing your SOPs, processing your subscription, and providing support when you ask for it.
We use your email address for transactional messages (account confirmations, password resets, receipts, sign-off notifications, and service notices), and, if you joined the waitlist or opted in, for launch announcements and product updates. Every non-transactional email has a working unsubscribe link, and unsubscribing never affects your access to the product.
We also use aggregated, non-identifying usage information to understand which templates and features are worth investing in.
We do not sell personal information, we do not share it with data brokers, and we do not use it for advertising or for cross-context behavioral profiling.
- 04
Service providers
We use a small number of processors to run the Service. Each one handles data only to perform services for us, under contract.
- Vercel: hosting for the site and the application, including request logs and delivery infrastructure. Vercel also receives page view and page speed measurements from Vercel Web Analytics and Vercel Speed Insights, described on the cookie policy, which set no cookie and write nothing to your device.
- Supabase: database and authentication. Your account, facility profile, and SOP content are stored here.
- Stripe: payment processing and subscription billing. Stripe is the controller of the card data it collects, under its own privacy policy.
- Anthropic: AI generation. Your facility profile and the relevant template content are sent to the Claude API to generate your documents. That content is not used to train models.
- PostHog: product analytics and session replay. Which features get used, so we know what to build next. In the application, and only where you have allowed analytics, we also record how the screen is used (clicks, scrolling and navigation) so that we can find and fix problems. Typed text, names, addresses, signatures and document contents are masked before anything leaves the browser, images and drawing areas are blanked, and recording never runs on the training sign-off screens that a tablet is handed around for. On the marketing site, the events we record when you submit a form are sent from our servers and store nothing on your device; anything that runs in your browser there has an entry of its own further down this list, and runs only where you have allowed it.
- Resend: email delivery. Transactional messages and, if you asked for them, product updates. Resend handles the address and the message in order to deliver it.
- Cloudflare: backup storage. Every night a copy of the database and of the files stored with it, including the signatures and photos attached to your training records, is encrypted and uploaded to a private bucket at Cloudflare R2 so that a deleted document can be recovered. Cloudflare holds ciphertext and does not hold the key. Each nightly set is deleted after thirty days.
- GitHub: the scheduled job that makes that backup. It runs on GitHub's hosted infrastructure, which is where the copy is taken from the database and encrypted before it leaves for Cloudflare, so GitHub is where the data is briefly handled in the clear. Nothing is kept there after the job ends.
- Google Analytics: counts visits and which pages get read, so we know which parts of the site are worth writing more of. It runs on the marketing site only, in your browser, and only where you have allowed it. Its own privacy policy is at https://policies.google.com/privacy.
- PostHog: times how fast pages load and respond in your browser, so we can tell a page that got slower from one that was always slow. It sends four numbers and the page path, and nothing about you. It runs on the marketing site only, in your browser, and only where you have allowed it. Its own privacy policy is at https://posthog.com/privacy.
- PostHog: product analytics and session replay: counts page views, and records how the page is used, meaning clicks, scrolling, navigation and which options you select, so that we can find and fix problems. The words on the page are our own public copy and are recorded as shown. Anything you type into a form or a calculator is masked before it leaves your browser, and the results a calculator works out from what you typed are blanked. It runs on the marketing site only, in your browser, and only where you have allowed it. Its own privacy policy is at https://posthog.com/privacy.
- 05
AI generation and your content
Generating an SOP means sending the template text and the parts of your facility profile that matter for that procedure to the Claude API, which returns the customized document. This is the mechanism by which the product works, and it is worth stating plainly rather than burying it.
That content is not used to train models, by Anthropic or by us. We do not use your facility data or your generated documents to build or improve any model, and we do not add your content to a shared template library.
We may retain generation inputs and outputs briefly for debugging and abuse prevention. If you would rather not send a particular detail to a third party, leave it out of your facility profile and add it to the document yourself after generation.
- 07
Your privacy choices
"Cookie preferences" reopens the chooser and changes any answer you gave, at any time, and turning something off actually stops it rather than only hiding it. The choice lives in your browser, so it is set separately on each device you use.
"Do Not Sell or Share My Personal Information" is next to it, and one click switches off Google Analytics and PostHog, along with everything else behind the product analytics and advertising switches. We do not sell personal information for money. It turns the lot off and removes what they wrote, and a Global Privacy Control signal does the same without you having to click anything.
If your browser sends a Global Privacy Control signal we honor it without asking you to confirm, for every visitor rather than only for residents of the states that require it. Access, correction, portability, deletion, and objection requests go to support@warehousesop.com and are honored regardless of where you live.
- 08
Data retention and deletion
We keep account data and SOP content for as long as your account is active, because it is the product. After an account is closed we retain the data for a short grace period so it can be recovered or exported, then delete it. Waitlist and sample download email addresses are kept until you unsubscribe or ask us to remove them. Server logs are kept for a limited period for security and debugging. Billing records are retained as long as tax and accounting rules require.
You can ask us to export or delete your personal information at any time by emailing support@warehousesop.com. We will confirm your request, act on it within thirty days, and tell you when it is done. Depending on where you live, you may have additional rights of access, correction, portability, or objection, and we honor those requests regardless of where you live.
Backups are the one place a deletion is not instant, and it is worth saying so rather than leaving you to assume otherwise. Every night an encrypted copy of the database and of the files stored with it goes to Cloudflare R2, each nightly copy is deleted after thirty days, and a copy taken before your deletion request therefore still contains your data until it ages out. Those copies exist to restore the whole product after a loss. They are restored whole or not at all, and we do not read an individual record out of one to bring it back.
- 09
Security
Data is encrypted in transit and at rest by our infrastructure providers, access to production systems is limited to the people who need it, and authentication is handled by Supabase Auth rather than by hand-rolled password code. No system is perfectly secure, and we will notify affected users and any required authority promptly if a breach affects personal information.
- 10
Changes to this policy
If we change what we collect, how we use it, or which processors we use, we will update this page and revise the effective date at the top. For material changes we will notify account holders by email before the change takes effect.
- 11
Contact
Questions, access requests, and deletion requests all go to support@warehousesop.com.