Legal
Privacy Policy
Last updated: September 2026
This is a draft. It's written to reasonably reflect what Configuro actually does today, but it has not been reviewed by a lawyer. Have it reviewed before relying on it with real customers and real data.
1. Who we are
Configuro is operated by Stackly Labs ("we", "us", "our"). This policy explains what data we collect through the Configuro Service, how we use it, and who we share it with.
2. What we collect
- Account data — name, email, password (hashed, never stored in plain text), and your organisation's name.
- Product and pricing data you configure — product families, options, rules, price lists. This is yours; we store it to run the Service.
- Customer/quote data your organisation collects through the configurator — your end customers' name, email, phone, company, and address, as entered when they request a quote. This data belongs to your organisation, not to us; we process it on your behalf.
- Billing data — handled directly by Stripe. We store a Stripe customer/subscription reference, never your raw card details.
- Usage data — login activity, feature usage, and error logs, used to operate and improve the Service.
3. How we use it
- To provide and operate the Service (authentication, rendering your products, calculating prices, generating quotes);
- To send transactional email (welcome/verification, password reset, quote and RFQ notifications, billing and trial reminders);
- To process payments and manage subscriptions;
- To respond to support requests and, occasionally, to tell you about material changes to the Service.
We do not sell your data or your customers' data to third parties, and we do not use your product, pricing, or customer data to train AI models.
4. Who we share it with (subprocessors)
We use the following third-party services to operate Configuro. Each only receives the data it needs to perform its function:
- MongoDB Atlas — database hosting for all account and application data.
- Railway — application hosting.
- Stripe — payment processing and subscription billing. Stripe receives your billing/payment details directly; we never see your full card number.
- Resend — transactional email delivery (account, quote, and billing emails).
- Anthropic (Claude) — powers the AI-assisted product builder ("Luigi") and in-configurator chat ("Ask Luigi"). Content you submit to these features (catalogue text, images, PDFs, chat messages) is sent to Anthropic to generate a response; it is not used to train Anthropic's models on our plan.
- Cloudflare R2 — file storage for uploaded images and documents (product photos, brochures).
5. Data retention and deletion
We keep your data for as long as your account is active. If your organisation's plan is cancelled, we retain data for a limited grace period (see our billing and retention policy) in case you reactivate, then delete it. You can request deletion of your account and associated data at any time by contacting us.
Quote-level customer data can also be auto-deleted after a retention period you configure yourself, in Branding settings — this is a GDPR-oriented control available to every organisation using Configuro to collect their own customers' data.
6. Cookies
The Configuro app uses essential cookies/local storage to keep you signed in. We don't currently use third-party advertising or tracking cookies on the application. The marketing site you're reading this on doesn't set tracking cookies either.
7. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data. To exercise any of these, email us at the address below — we'll respond within a reasonable time.
8. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll notify account admins by email before it takes effect.
9. Contact
Questions about this policy, or a data request? Email hello@configuro.net.