Skip to main content
Back to home

Privacy Policy

How InstoreX collects, uses and protects personal data — both on this website and inside the InstoreX service.

Last updated: 2026-07-29

On this page

  1. 1. Who we are
  2. 2. Two different roles, two different sets of rules
  3. 3. What we collect from website visitors
  4. 3a. Cookies and your choice about analytics
  5. 4. Why we use it, and on what legal basis
  6. 5. How long we keep it, and who else sees it
  7. 6. Conversations recorded through the service
  8. 7. Sub-processors
  9. 8. International transfers
  10. 9. Security
  11. 10. Your rights
  12. 11. Children
  13. 12. Changes to this policy

1. Who we are

InstoreX ("we", "us") operates the website at instorex.co and the InstoreX application at app.instorex.co. InstoreX analyses recorded in-person sales conversations on behalf of retailers and other businesses.

You can reach us about anything in this policy, including any request to exercise your rights, at hello@instorex.co.

2. Two different roles, two different sets of rules

This policy covers two distinct relationships, and the difference matters for your rights.

  • Website visitors and prospects. When you browse instorex.co or ask us for a demo, we decide why and how your data is used. In GDPR terms we are the controller, and sections 3 to 5 apply to you.
  • People recorded on a customer's sales floor. When a business uses InstoreX to analyse conversations in its stores, that business decides what is recorded, why, and for how long it is kept. That business is the controller; we act as its processor and only do what its instructions and our contract permit. Section 6 explains what that means for you, and who to contact.

3. What we collect from website visitors

We keep this deliberately small. From visitors to this website we collect only:

  • Demo request details — the work email, full name and job title you type into the "Book a demo" form, plus the fact and time of your request and whether you ticked the marketing consent box.
  • Technical request data — the IP address, browser user-agent and requested URL that any web server necessarily receives in order to answer a request, held in short-lived server logs by our hosting provider.
  • Analytics about your visit — which pages you viewed and in what order, what you clicked, your approximate location derived from your IP address, and your device and browser type, together with a replay of your visit to this website. This is collected by PostHog and only where section 3a says we are allowed to collect it.

We run no advertising cookies and no ad-network tracking scripts. We do not buy or sell contact data, and we do not share what we measure here with advertisers.

3a. Cookies and your choice about analytics

A cookie notice appears on your first visit and your answer is remembered. You can change it at any time through the "Cookie settings" link in the footer of every page on this site.

Cookies and similar storage used by this website
NameSet byWhat it is forHow long it lasts
instorex.consent.analyticsThis websiteRemembers whether you allowed analytics, so you are not asked againUntil you clear your browser storage
ph_* (for example ph_phc_…_posthog)PostHogDistinguishes one visit from another and links the pages of a single session, so the analytics above are possible12 months

The consent record is strictly necessary — it exists only to honour your choice, and there is no version of this site that can respect an answer without storing it. The PostHog cookies are not, and are governed by the choice you make.

What happens before you answer depends on where you are, because the law does. If you are in the EEA, the UK or Switzerland, nothing is measured and no analytics cookie is set until you accept — the notice asks, and declining is a single click alongside accepting. Elsewhere, including the United States, analytics start when the page loads and the notice tells you so; declining through the notice or the footer link stops collection from that moment. Where we cannot tell which applies, we treat you as being in the first group.

PostHog masks the contents of form fields before a session replay leaves your browser, so what you type into the "Book a demo" form is not captured by the replay. Your browser's own "Do Not Track" and Global Privacy Control signals are respected where PostHog receives them.

4. Why we use it, and on what legal basis

Purposes and legal bases for website visitor data
What we doWhyLegal basis (GDPR Art. 6)
Reply to your demo request and arrange a callYou asked us toSteps taken at your request prior to a contract, Art. 6(1)(b)
Send you occasional marketing about the productOnly where you ticked the consent boxConsent, Art. 6(1)(a) — withdrawable at any time
Measure how the website is used, including session replayTo see which pages help and where visitors get stuckConsent, Art. 6(1)(a) — see section 3a, and withdrawable at any time
Keep server logs and block automated abuseSecurity and availability of the siteLegitimate interests, Art. 6(1)(f)
Keep records of contracts and correspondenceAccounting and defending legal claimsLegal obligation and legitimate interests, Art. 6(1)(c) and (f)

Withdrawing marketing consent is a single email to us and takes effect immediately; it does not affect processing carried out before you withdrew it, and we will still answer an open demo request.

5. How long we keep it, and who else sees it

  • Demo requests are kept for as long as we are in contact with you about becoming a customer, and for up to 24 months after our last contact, after which they are deleted.
  • Server logs are kept for a short operational period by our hosting provider and then rotated out.
  • Analytics events are kept for up to 12 months and session replays for 30 days, after which PostHog deletes them.
  • Records we are required to keep for tax or accounting purposes are kept for the period the applicable law requires.

We share website visitor data only with the service providers that make the website work — our hosting and deployment provider, our email provider, and PostHog for the analytics described in section 3a — each under a written contract that limits them to processing on our instructions. We do not share it with anyone else, and we never sell it.

6. Conversations recorded through the service

If you spoke to a salesperson in a store that uses InstoreX, this section is the one that concerns you.

The store — not us — decides that recording happens, is responsible for telling you about it and for obtaining your consent where the law requires it, and sets how long recordings are kept. We process the audio strictly on that store's instructions.

What we do with a recording, in order:

  • Transcribe it and separate it into speakers, using a specialist speech-to-text provider.
  • Redact direct identifiers. Names, phone numbers, national ID numbers, email addresses and payment details are detected and removed from the transcript before the analysis stage runs.
  • Analyse the redacted transcript against the store's own sales playbook, producing scores and coaching notes about the salesperson's technique.

The output is about how the salesperson sold, not about who the customer is. We do not use recordings or transcripts to build customer profiles, to make automated decisions that produce legal or similarly significant effects about you, or to train our own or any third party's general-purpose AI models.

Because the store is the controller, requests to access or delete a recording of you should go to that store, which is obliged to answer them. If you contact us instead we will pass the request on and tell you who it went to. You can always reach us at hello@instorex.co.

7. Sub-processors

We use the following providers to deliver the service. Each is bound by a data processing agreement, and we remain responsible to our customers for what they do.

Sub-processors used by the service
ProviderWhat it doesWhere it processes
ElevenLabsSpeech-to-text transcription and speaker separationUnited States
OpenAIAnalysis of the redacted transcript against the sales playbookUnited States
VercelWebsite and application hostingUnited States and EU
PostHogWebsite analytics and session replay — this website only, never recordings or transcriptsUnited States

We give customers advance notice of a change to this list, so that they can object before it takes effect.

8. International transfers

Some of the providers above process data outside the European Economic Area and outside Israel, principally in the United States. Where personal data leaves the EEA we rely on the European Commission's Standard Contractual Clauses, together with technical measures including encryption in transit and the redaction described in section 6. Israel benefits from a European Commission adequacy decision.

9. Security

  • All traffic to and from our website, application and providers is encrypted in transit using TLS.
  • Access to customer data is limited to the personnel who need it and is authenticated individually.
  • Direct identifiers are removed from transcripts before the analysis stage, so the stage that reasons about a conversation does not receive them.
  • Provider API credentials are held as server-side secrets and are never embedded in the pages this website serves.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where the law requires it, you.

10. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — a copy of the data we hold about you.
  • Rectification — correction of data that is wrong or incomplete.
  • Erasure — deletion, where we have no overriding basis to keep it.
  • Restriction and objection — including an absolute right to object to direct marketing.
  • Portability — a machine-readable copy of data you gave us.
  • Withdrawal of consent — at any time, without affecting prior processing.
  • Non-discrimination — under California law, we will not treat you worse for exercising a privacy right. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.

To exercise any of these, email hello@instorex.co. We answer within 30 days. If you are in the EEA or the UK you may also complain to your national data protection authority; if you are in Israel you may complain to the Privacy Protection Authority (opens in a new tab).

11. Children

This website and the service are intended for businesses and are not directed at children. We do not knowingly collect personal data from children. If you believe a child's data has reached us, contact us and we will delete it.

12. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects your rights we will make it prominent on the site, and where we relied on your consent we will ask again rather than assume it carries over.

Privacy Policy Terms of Use Accessibility Statement
© InstoreX · in-person sales intelligence