ParcelKind by Styrvia — Privacy Notice
Version: PK-PRIVACY-2026-09-24-v9
Effective date: 24 September 2026
Service scope: ParcelKind account, verified email/password, optional authenticator-app 2FA and optional cloud workspace sync
1. Controller and contact
Styrvia, CVR 46690397, Monica Zetterlundsvej 19, 4. tv., 2450 Copenhagen SV, Denmark is the controller for ParcelKind account/authentication data, the ParcelKind website, trial and entitlement administration, legal-acceptance records, support and business correspondence, service-delivery/security information and any other personal-data processing specifically described in this Notice.
Contact: https://styrvia.com/contact or support@styrvia.com.
ParcelKind is separate from Styrvia’s financial-planning products. ParcelKind account/security data and Styrvia financial-planning data are not intended to share a product database.
2. Privacy boundary: optional cloud sync
The account-enabled ParcelKind release uses a central account so Styrvia can authenticate access, protect the account with a password and optional authenticator-app 2FA, administer the trial/entitlement, record legal acceptance and operate security controls.
Your working compliance workspace stays on your device by default. If you choose Enable cloud sync, the app sends a copy of the working workspace to the Supabase project associated with your account. It then sends changes as you work. The cloud copy includes the retained order and listing fields, packaging recipes, mappings, supplier and registration notes, evidence metadata, reports and workspace history. It is a synced working copy, not a statutory archive or a filing service. The app does not upload the original Etsy CSV file itself.
A cloud copy can be opened on another signed-in device. If two copies differ, sync pauses and asks you to choose; it does not silently replace either copy. You may pause sync on a device or delete the cloud copy from the workspace. Pausing does not delete the existing cloud copy. The copy remains available to your account until deleted through the app or account-deletion process.
3. Account and authentication data
To operate the account service, Styrvia may process:
- your account identifier and contact email used for the account;
- password-verification data. Styrvia must not intentionally store your password in plaintext;
- authenticator-app 2FA enrollment and verification data, if you enable 2FA;
- security and session information needed to authenticate the account, manage active sessions, detect abuse and protect sign-in;
- account creation, status and security-event timestamps;
- trial/entitlement status;
- Terms/Privacy acceptance records, containing account reference, version identifiers and a database-generated acceptance time (the current record does not include a document hash or release context); and
- recovery/security state where the released account flow provides it.
Authentication data is separate from the compliance workspace, whether device-local or optionally synced.
Never send your password, live 2FA code or authenticator setup secret to Styrvia support.
4. Passwords and 2FA
ParcelKind requires verified email and password authentication. Authenticator-app 2FA is optional to enable; once enabled it is required at each new sign-in. You can turn it off from Account security only after verifying an authenticator code in the current session; the app then signs you out. After enrollment, ParcelKind issues eight one-time recovery codes. The service stores cryptographic hashes of the codes, their usage status and limited failed-attempt/rate-limit data in Supabase. Plaintext codes are shown only once and are not included in the cloud workspace. A code plus a valid password session can remove the enrolled authenticator and signs you out; previous codes are revoked. If you lose both your authenticator and the codes, support identity verification may be needed. Access to a cloud copy still requires successful account access.
Passwords must be protected using one-way password-verification mechanisms rather than stored as readable plaintext.
2FA and recovery-code data is processed only as needed to enroll, verify, secure, recover and remove a factor. Failed code attempts are rate-limited. The recovery-code hashes and attempt state are deleted when codes are rotated, revoked or the account is deleted. If you lose the authenticator and all codes, recovery is support-led.
The exact recovery controls available to you are the controls presented by the released application. Styrvia cannot restore a workspace that exists only on your device. An optional cloud copy may be reopened after account access is restored, subject to availability and the limits of the service.
5. Compliance workspace
Depending on what you enter or import, the local workspace may contain:
- seller and business setup facts;
- selected Etsy order and reconciliation fields;
- destination activity;
- listing and variation mappings;
- packaging recipes, components, materials, weights and weight-source information;
- registration, scheme, representative or marketplace-related records you enter;
- supplier, manufacturer, declaration or other evidence-status information;
- PPWR/EPR role and readiness results;
- country/material calculations;
- review items;
- reports, finalised snapshots and local workspace history.
This information remains on your device unless you enable cloud sync or deliberately export, copy or share it. The cloud copy is stored as an account-scoped record in Supabase with row-level access rules. Styrvia administrators and its service provider may have operational access as required to run, secure or support the service; it is not end-to-end encrypted from Styrvia.
6. Etsy CSV data minimisation
The current import flow uses an Etsy Orders-by-Item CSV selected by you and does not require an Etsy login or Etsy OAuth/API connection.
The import flow is designed to retain the fields needed for calculation and reconciliation and to discard buyer names, street addresses, email addresses and prices where they are not needed.
You control the source file you select. Avoid importing or retaining unnecessary personal data.
Styrvia does not receive the original Etsy CSV merely because you import it. If you enable cloud sync, the retained fields derived from that CSV become part of the synced workspace.
Etsy is not a ParcelKind processor or recipient merely because a CSV file originated from Etsy.
7. Browser storage, cloud sync, backups and deletion
Browser storage is not a backup. Cloud sync is a working copy, not a guaranteed archive.
If you clear browser data, change browser profiles, lose the device or experience a browser/device failure, local workspace data may be lost even though your ParcelKind account still exists.
Use ParcelKind’s export/backup functions to keep a copy somewhere you control.
You can delete an enabled cloud copy in the app without deleting the browser copy. To remove browser copies, clear the site storage on each device. Exported backups are under your control. Request account deletion through support@styrvia.com; this is a handled request, not an automatic button. Before account closure you may export a backup. Styrvia will delete the active cloud workspace as part of account deletion, subject to the backup cycle below. Deleting an account cannot erase exported files or copies remaining on your devices.
8. Website, account delivery and security
When you visit ParcelKind, create/sign in to an account, or use the account service, standard technical information may be processed to deliver and protect the service. This can include IP address, request metadata, timestamps, session/security state, authentication events, security events and server/edge logs.
Cloudflare provides website/application delivery and security infrastructure and may process this technical information. Supabase Auth provides account authentication, password verification, optional TOTP factors, session security and password-reset/verification email flows; the legal-acceptance and optional cloud-workspace tables are in the matching Supabase project.
Where the shared Styrvia contact flow uses Cloudflare Turnstile, Cloudflare also processes the technical information needed to provide that abuse-protection service.
The purposes are account/service delivery, authentication, session management, security, abuse prevention, incident investigation and troubleshooting.
9. Website analytics
ParcelKind public information pages can use Cloudflare Web Analytics only after you select Allow analytics. The optional beacon is not loaded before that choice and is never loaded inside the signed-in workspace or account callbacks. You can change your choice through the Analytics choice link in the public-page footer. If no analytics token is configured, no beacon or choice banner is shown.
Analytics is intended to count visits and performance on public pages. It must not receive Etsy orders, packaging recipes, registrations, evidence files, account passwords, 2FA data or local workspace contents. The choice is kept in browser storage so it can be respected on later visits.
The optional beacon is enabled only when the site has been configured with its Cloudflare Web Analytics token and the visitor has allowed it.
10. Pilot access, support and contact
ParcelKind support uses the shared Styrvia contact process.
When you contact Styrvia, Styrvia receives the information you deliberately submit, which may include your name, email address, business/contact details, selected topic and message.
The current shared support/contact chain uses:
- Cloudflare / Cloudflare Turnstile for website delivery, security and abuse protection where used by the form;
- Brevo for contact-form message processing/routing; and
- Google (Gmail) for the current Styrvia support mailbox.
Support correspondence is separate from your compliance workspace.
Do not send buyer names, street addresses, full unredacted Etsy exports, passwords, live 2FA codes, authenticator setup secrets, registration credentials or confidential supplier evidence through ordinary support unless Styrvia specifically requests a limited item through an appropriate secure process.
11. Email updates and marketing
Account or security communications are separate from marketing.
Creating a ParcelKind account, accepting Terms, requesting pilot access or contacting support does not by itself subscribe you to marketing.
If Styrvia later offers ParcelKind product, regulatory or marketing emails, it will use a separate consent or other valid legal basis where required. Any ParcelKind marketing consent should remain distinguishable from consent for Styrvia’s other products.
Where consent is used, you can withdraw it using the unsubscribe mechanism provided or by contacting Styrvia.
12. Trial, payments and subscriptions
The account-enabled release may centrally store the start/end or status information needed to enforce the current 30-day no-card trial.
The trial does not require a payment card. Paid checkout is not active in the current service; any later paid order requires a separate confirmation.
No payment-card data is collected in the current ParcelKind trial.
Before paid processing begins, this Notice must identify the actual payment provider, billing data and retention; checkout must show the billing and cancellation conditions. The current text does not authorise undisclosed payment processing.
13. Purposes and legal bases
Where the GDPR applies, Styrvia processes the personal data it actually receives for the following purposes and legal bases, depending on the interaction:
- creating and administering your ParcelKind account, authentication, 2FA, sessions, trial/entitlement and requested service access, including optional cloud sync when you enable it — performance of the service relationship and steps at your request;
- account/service security, abuse prevention, authentication integrity, fraud/security investigation and troubleshooting — Styrvia’s legitimate interests in operating and protecting ParcelKind;
- recording the Terms/Privacy versions you accepted and the database acceptance time — performance of the service relationship and Styrvia’s legitimate interests in administering the contractual relationship and demonstrating the applicable service terms;
- support and requested business communications — performance of the service relationship, steps at your request and/or legitimate interests in responding to users;
- legal, accounting, dispute or compliance records where required — compliance with legal obligations and/or legitimate interests in establishing, exercising or defending legal claims;
- email marketing or optional communications where consent is required — consent.
Styrvia does not receive a workspace kept only on a device. When you enable cloud sync, Styrvia and Supabase process the account-scoped workspace to provide that requested feature.
14. Retention
Device-local compliance workspace: retained under your control until you delete it, clear browser storage or otherwise remove it.
Optional active cloud workspace: retained while you keep it in your account. Deleting it removes the active database row; residual copies in provider backups may remain until backup rotation completes. Cloud sync is a working copy, not a promised statutory archive. The backup rotation and deletion timetable must be documented before broad release.
Active account/authentication records: retained while needed to operate your account and the service.
Password-verification and optional 2FA/security material: retained only for as long as needed to authenticate and secure the account, subject to the account-deletion, security and legal-retention rules below.
Legal-acceptance and security records: may be retained after account closure where reasonably necessary to demonstrate the applicable Terms, investigate security events, comply with law, or establish, exercise or defend legal claims.
Ordinary support and business correspondence: normally retained for no longer than 12 months after the matter is resolved, unless longer retention is reasonably necessary for an unresolved dispute, legal obligation or legal claims.
Sensitive support files specifically requested by Styrvia: deleted as soon as they are no longer needed and in any event within 30 days after the support issue is resolved, unless a legal obligation requires otherwise.
Website/security data processed through Cloudflare: retained according to the security, troubleshooting and provider/account settings applicable to the service and only for as long as reasonably necessary for those purposes.
Optional public-page analytics: only after the visitor allows it and the Cloudflare beacon is configured. The period for which Cloudflare keeps analytics data depends on the configured service settings; Styrvia must record and disclose that period before activating the token.
15. Recipients and service providers
For the account-enabled release, recipients may include only the service providers needed for the processing described above, including:
- Cloudflare — website/application delivery, security and Turnstile where used;
- Supabase — account authentication, password-verification and recovery, optional TOTP factors, sessions, legal-acceptance records and optional cloud-workspace sync;
- Brevo — shared Styrvia contact-form message routing/processing; and
- Google (Gmail) — current Styrvia support mailbox.
No payment processor is connected to the current ParcelKind trial.
Styrvia does not sell ParcelKind personal data.
Etsy, regulators, PROs, EPR schemes, suppliers and laboratories do not automatically receive your workspace from Styrvia. If you export or send information to them yourself, that processing is governed by your relationship with that recipient.
Any separate transactional-email provider for account verification or password recovery must be identified in this Notice before that provider begins processing account data.
16. International transfers
Some service providers may process personal data outside Denmark or the EEA.
Where GDPR restrictions on international transfers apply, Styrvia will use an applicable transfer mechanism and safeguards required for the relevant processing.
You may contact Styrvia for current information about the providers and safeguards applicable to your data.
17. Cookies, sessions and similar technologies
The account-enabled ParcelKind release uses browser local storage for its authentication session and a last-activity timestamp, with a 30-minute inactivity sign-out. These are strictly necessary authentication/session mechanisms to keep you signed in and protect the account. The workspace uses separate device-local storage. A browser script compromise could expose locally held session tokens; keep your browser and device secure.
These mechanisms are used for account/session operation and security, not for advertising.
Cloudflare may also use technical or strictly necessary security mechanisms when required to deliver or protect the service or shared contact form.
ParcelKind does not currently operate advertising cookies.
The optional public-page analytics beacon is controlled by the Allow analytics choice. It stays off when no token is configured or the visitor keeps it off.
18. Account deletion and privacy requests
You may request deletion of the central ParcelKind account through the available account/privacy process.
Contact support@styrvia.com to request account deletion. Styrvia will verify the request, remove the active cloud workspace, assess any separate legal-acceptance retention basis, remove the Auth account, and confirm completion. We will complete eligible active-account and cloud deletion without undue delay and within one month of receipt, subject to identity verification, any applicable legal exception and a lawful extension where permitted. We will respond to a rights request within the GDPR deadline. Records Styrvia must or may lawfully retain for security, legal obligations, dispute handling or legal claims are assessed separately, with access limited to that purpose. Account deletion does not remove workspace data remaining only on your device/browser; clear it separately.
Likewise, deleting local browser data does not automatically delete the central account.
19. Your rights
Where the GDPR applies and subject to its conditions and exceptions, you may have rights to:
- access personal data Styrvia holds about you;
- rectify inaccurate personal data;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive portable data where the portability rules apply; and
- withdraw consent where processing is based on consent.
These rights apply to personal data Styrvia actually holds. Styrvia cannot provide a server copy of a workspace that was never synced or shared.
You may also complain to the Danish Data Protection Agency (Datatilsynet) or another competent supervisory authority.
To make a privacy request, use https://styrvia.com/contact and select the privacy/GDPR topic, or contact support@styrvia.com.
20. Security
Styrvia uses technical and organisational measures intended to protect the website, account service and personal data it receives.
The account-enabled release uses verified email/password authentication with optional authenticator-app 2FA. Cloud sync is optional, uses per-account database access rules, and is not end-to-end encrypted. Avoid placing unnecessary buyer personal data or confidential files in the workspace.
You remain responsible for protecting your own device, browser profile, password, authenticator access, exports and backups.
21. Changes to this Notice
Styrvia may update this Notice when ParcelKind’s architecture, providers, account model, analytics, payments, support process or legal obligations change.
Material new processing will not be silently treated as covered by an unrelated prior consent.
If ParcelKind later introduces automatic archival backup, a payment processor, new authentication/recovery providers or other central processing not described here, this Notice must be updated before that processing is enabled.
22. Contact
Styrvia
CVR 46690397
Monica Zetterlundsvej 19, 4. tv.
2450 Copenhagen SV
Denmark
https://styrvia.com/contact
support@styrvia.com
