1. Who we are
Rosta Suite ("Rosta", "we", "us") is an inventory, order and accounting platform operated by Galaxy Professionals. Rosta connects a merchant's sales channels — such as Shopify, Etsy, eBay, Amazon and WooCommerce — to a single inventory and accounting system.
This policy explains what personal data we process, why, and how we protect it.
Our role. When a merchant connects their store to Rosta, the merchant is the data controller of their customers' personal data. Rosta acts as a data processor on the merchant's behalf and processes that data only to deliver the service described below.
2. Data we process
2.1 Merchant account data (we are the controller)
- Name, business name, email address and phone number of the account holder and any users they invite
- Login credentials (passwords are stored only as salted hashes — never in plain text)
- Billing and subscription records
- Support correspondence
- Application logs and usage records
2.2 Store data received from connected sales channels
When a merchant authorizes a channel connection, we receive:
- Order data — order number, date, line items, SKUs, quantities, prices, taxes, totals
- Product and inventory data — product names, SKUs, costs, prices, stock levels, locations
- Customer data attached to orders — name, email address, phone number, shipping and billing address
We receive this data only for stores the merchant has explicitly connected, and only through the permissions (scopes) the merchant approves during authorization.
2.3 Data we do not process
We do not receive, request or store payment card numbers, bank account details, or authentication credentials for a merchant's end customers.
3. Why we process it
We process personal data only to provide the service the merchant has asked for:
| Purpose | Data used |
|---|---|
| Import orders from connected channels into the merchant's Rosta account | Order data, customer name, email, phone, address |
| Create the corresponding customer record, invoice and accounting entries | Customer name, email, phone, address |
| Deduct stock and push updated inventory levels back to the merchant's channels | Product, SKU and inventory data |
| Provide inventory, sales and accounting reports to the merchant | Order and product data |
| Operate, secure, support and troubleshoot the service | Account data, logs |
| Bill the merchant for the service | Merchant account and billing data |
We do not use personal data for advertising, marketing, profiling, personalization, resale, or automated decision-making that produces legal or similarly significant effects. We do not sell personal data.
4. Legal bases (where GDPR / UK GDPR applies)
- Contract — to provide the service the merchant has subscribed to
- Legitimate interests — to secure, maintain and improve the service, and to prevent fraud and abuse
- Legal obligation — where we are required to retain records by law
For end-customer personal data received from a merchant's store, the merchant is responsible for establishing the legal basis and for providing notice to their customers.
5. Where data is stored
Rosta runs on Microsoft Azure. Merchant data is stored in Azure SQL databases hosted in the United States.
Tenant isolation. Each merchant's business data is stored in its own dedicated database. Merchant data is not commingled in a shared application database.
If you are located outside the United States, be aware that your data will be transferred to and processed in the United States. Where required, we rely on Standard Contractual Clauses or an equivalent transfer mechanism.
6. How we protect it
- Encryption in transit — all connections use TLS
- Encryption at rest — Azure SQL Transparent Data Encryption; automated backups are encrypted
- Credential protection — channel API secrets are stored encrypted; passwords are stored as salted hashes
- Access control — role- and permission-based access within the application; administrative access to production is limited to personnel who need it
- Separation of environments — test and staging environments use separate databases from production
- Audit logging — administrative and data-changing actions are recorded in an audit log
- Webhook verification — inbound webhooks from sales channels are verified using HMAC signatures before being accepted
No system is perfectly secure, but we work to protect data using the measures above and review them as the service develops.
7. Sub-processors
We use the following third parties to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, backups, transactional email | United States |
| Stripe | Subscription billing and payment processing | United States |
We do not sell, rent or share personal data with any other third party, except where required by law.
8. How long we keep data
| Data | Retention |
|---|---|
| Store and order data in an active account | For as long as the account is active |
| Store and order data after a merchant disconnects a channel or cancels | Deleted within 30 days, unless the merchant asks for earlier deletion |
| Merchant account and billing records | Retained as required for tax and accounting purposes, then deleted |
| Application logs | 90 days |
| Backups | Overwritten on the platform's backup rotation schedule |
When a merchant uninstalls the app or deletes their account, we delete their store data in line with the periods above and honour Shopify's mandatory shop/redact and customers/redact requests.
9. Merchant and customer rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, or to object to processing.
Merchants can exercise these rights by contacting us at info@galaxyprofessionals.com.
End customers of a merchant's store should contact the merchant directly — the merchant is the controller of that data. Where a merchant asks us to delete or provide a customer's data, we act on that request. We also act on the deletion and data-request webhooks sent by connected platforms.
We respond to verified requests within 30 days.
10. Children
Rosta is a business tool and is not directed to children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy as the service changes. We will post the updated version here and change the "Last updated" date. Where changes are material, we will notify account holders by email.
12. Contact
Galaxy Professionals Tonawanda, New York, United States info@galaxyprofessionals.com