Skip to main content
Legal center

Naara policies

Privacy Notice

This policy explains how Naara handles personal, account, and organization information when providing its inventory management platform.

Last updated: September 17, 2026

About this Privacy Notice

This Privacy Notice explains how Naara Logistics Inc., a Delaware corporation doing business as Naara ("Naara," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit www.naarainventory.com, create or use a Naara account, communicate with us, or otherwise use a service that links to this Notice.

This Notice applies to website visitors, prospective customers, account users, customer and supplier contacts, shipping recipients, and other individuals whose information may be processed through Naara. It does not govern an independent third-party service, even when that service can be accessed through Naara.

Our role and your organization's role

Naara determines how and why it processes personal information concerning website visits, account registration, subscriptions, billing administration, support, service security, and Naara's own operations. For this information, Naara generally acts as the data controller or business.

A customer organization generally controls the business information it enters or imports about its employees, customers, suppliers, delivery recipients, and other contacts. For that information, the customer organization generally acts as the controller or business, and Naara acts as its processor or service provider.

If your information was entered into Naara by a customer organization, you should normally direct your privacy request to that organization. Naara will assist the organization where required by law and our agreement with it.

Information we collect

Account and identity information may include your name, email address, telephone number, profile image, job title, organization, assigned location, account status, roles, permissions, login activity, authentication records, password hash, and session information. Naara does not need to know or store your readable password.

Organization information may include an organization's name, industry, contact information, address, country, state, currency, time zone, staff-size range, business locations, subscription plan, billing contact, and onboarding choices.

Operational information entered or imported by a customer may include inventory and catalog records; suppliers and customers; purchases, sales, returns, credits, and payments; POS reports; uploaded invoices, receipts, delivery notes, images, and spreadsheets; marketplace requests; and shipping origins, destinations, recipients, labels, and tracking information.

Billing information may include billing contacts, subscription status, payment status, invoices, and transaction identifiers. Complete card numbers and security codes entered through Stripe-hosted checkout are processed by Stripe and are not intended to be stored by Naara.

Technical and security information may include IP address, browser and device type, operating system, access time, requested pages or functions, essential cookie and session identifiers, login attempts, error information, and security or audit events.

Customers should not place passwords, payment-card numbers, government identification numbers, health information, or other unnecessary sensitive information in notes, uploaded documents, or general-purpose fields.

Sources of information

We receive information directly from you; from the organization that creates, administers, or invites you to an account; from authorised users within that organization; from files and records entered by customers; automatically through use of the service; from customer-selected integrations; and from payment, email, file-storage, hosting, shipping, and security providers.

How we use information

We use personal information to create and administer accounts; provide inventory and business-management functions; enforce organization boundaries, roles, and permissions; process subscriptions; send authentication and operational messages; provide support; operate customer-selected integrations; generate requested reports; detect fraud and security threats; diagnose errors; improve reliability and usability; maintain audit records; enforce agreements; and comply with legal, accounting, tax, and regulatory obligations.

Where applicable law requires a legal basis, we rely on performance of a contract, steps requested before entering a contract, compliance with law, our legitimate interests or those of our customers, or consent where consent is required. Consent may be withdrawn prospectively without affecting processing that was lawful before withdrawal.

We may use aggregated or de-identified information to understand service usage, capacity, reliability, and business performance. We do not attempt to reidentify properly de-identified information except to test whether the protective measures remain effective.

Naara reports are intended to assist people with business decisions. Naara does not currently use personal information to make solely automated decisions that produce legal or similarly significant effects concerning an individual.

How we disclose information

Information in an organization is available to authorised users according to that organization's roles and permissions. Organization owners and administrators control whom they invite and what access those users receive. Naara platform access is separate and limited to authorised operational, support, security, and administrative purposes.

Our production application and primary PostgreSQL database are hosted by Railway in the United States. We also use Stripe for subscription billing, Resend for transactional email, UploadThing for authorised file storage, and Shippo for customer-selected shipping functions. These providers receive only the information reasonably necessary to perform the relevant service, subject to their agreements and legal obligations.

When an organization enables an integration, we disclose the information required to perform the requested function. Information an organization intentionally publishes through marketplace features may be visible to the selected audience, and fulfilment details may be disclosed to participating organizations and shipping providers.

We may disclose information to professional advisers; when required by law or valid legal process; to protect Naara, our customers, users, or others; to investigate fraud, abuse, or a security incident; or as part of a financing, merger, acquisition, reorganization, sale of assets, or similar transaction subject to appropriate safeguards.

Cookies, embedded content, and advertising

Naara uses essential cookies and similar technologies for authentication, secure sessions, misuse prevention, routing, and requested service functionality. Our Cookie Notice provides more information and explains browser controls.

Naara does not currently use PostHog, Vercel Analytics, advertising pixels, or other non-essential analytics technologies in production. Naara does not sell personal information or share it for cross-context behavioural advertising.

An embedded YouTube video may allow YouTube to process device, cookie, or interaction information when the video is loaded or used. YouTube handles that information under its own terms and privacy notice.

Because Naara does not currently conduct cross-site behavioural tracking, browser Do Not Track signals do not change the service's operation. Where legally required, we will treat a recognised Global Privacy Control signal as a request to opt out of the sale or sharing of personal information.

International processing

Naara's production application and primary database are hosted in the United States. Some service providers may process information in other countries under their own infrastructure and legally required transfer safeguards.

Where applicable law requires a transfer mechanism or other safeguard for cross-border processing, Naara will use an appropriate mechanism and provide related contractual information to customers.

Data retention and export

Naara retains account and Customer Data for the duration of the customer relationship and afterward only as reasonably necessary to complete account closure, support an authorised export or transition, follow customer instructions, maintain limited backups, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, prevent fraud, enforce agreements, and maintain security and audit records.

Historical orders, returns, credit movements, inventory movements, shipments, and related audit records may be archived rather than destructively deleted while the organization account remains active because these records preserve operational and financial integrity. Subscription downgrades do not intentionally delete customer data.

When continued retention is no longer necessary, Naara deletes or de-identifies the information, subject to standard backup-expiration processes and applicable law.

Security

We use administrative and technical safeguards designed to protect information, including organization boundaries and role-based access controls. No online system can guarantee absolute security.

Customers are responsible for protecting login credentials, assigning appropriate permissions, and promptly reporting suspected unauthorised access.

Your privacy rights

Depending on applicable law and your location, you may have rights to be informed; access or receive a copy of personal information; correct inaccurate information; request deletion; restrict or object to processing; obtain certain information in a portable format; withdraw consent; opt out of certain sales, sharing, marketing, or targeted advertising; request human review of certain automated decisions; and complain to an appropriate regulator.

We may need to verify your identity and authority before acting on a request. Applicable law may permit or require us to retain information or deny part of a request. If information is controlled by a Naara customer organization, we may refer the request to that organization.

We will not unlawfully discriminate against an individual for exercising a privacy right. Subscription, authentication, security, and other operational communications may remain necessary to provide the service. Optional marketing messages will include an appropriate way to opt out.

California disclosures

During the preceding 12 months, Naara may have collected identifiers and contact information; customer-record information; commercial and transaction information; internet or electronic-network activity; professional or employment-related information; account login and authentication information; uploaded content that may contain personal information; and approximate location derived from an IP address where available.

The sources, purposes, retention criteria, and recipients for these categories are described in this Notice. Naara has not sold personal information or shared it for cross-context behavioural advertising, and it does not use sensitive personal information to infer characteristics about individuals.

Where the California Consumer Privacy Act applies, a California resident may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, use an authorised agent, and receive equal service when exercising those rights.

Age requirement

Naara is a business service and is not directed to children. You must be at least 18 years old to create or use a Naara account. We do not knowingly collect personal information directly from anyone under 18 through an account. If we learn that we collected a minor's information contrary to applicable law, we will take appropriate steps to delete it.

Policy updates

We may update this policy as Naara develops. Material changes will be communicated through the service or appropriate contact channels, and the updated date will appear on this page.

Additional U.S. state disclosures

Residents of U.S. states with comprehensive privacy laws can review Naara's category-level notice at collection, state-law disclosures, and request instructions in the Additional U.S. State Privacy Disclosures.

Contact us

Questions or privacy requests can be sent to Naara Logistics Inc., 8 The Green, Dover, DE 19901, United States, or by email at support@naara.com.