Helny — Privacy Policy
Helny is a business management application for antique and second-hand shops, developed and operated by Go Upstream AB ("we", "us"). This policy explains what personal data the app processes, why, and the choices you have. It applies to the Helny app and its connected services.
1. Who is responsible for your data
Helny is used by antique/second-hand shops to manage their inventory, sales and marketing. For the business data that a shop enters and for data from the shop's own connected accounts (such as its Instagram Business account), the shop is the data controller and Go Upstream AB acts as a data processor on the shop's behalf. For the operation of the app itself and its user accounts, Go Upstream AB is the controller.
2. Data we process
- Account data — name and email address of the shop's users, used to sign in and share data within the shop.
- Business data — inventory items, prices, photos, sales and daily cash reports that the shop enters or that are synced from the shop's point-of-sale.
- Instagram data — for a shop that connects its Instagram Business account: the shop's own posts, and the comments on those posts (comment text, the commenter's username and timestamp). See section 4.
- Point-of-sale data — sales transactions retrieved from the shop's connected iZettle/Zettle account for daily reconciliation.
- Agreement records — when a shop signs up on helny.app, the name, email address (confirmed with a one-time code) and phone number of the person who accepts the agreement, the time, the terms version, a one-way hash of the IP address and the browser identification. We keep this as our record that the agreement was made, and act as controller for it, not as the shop's processor.
- Demo contact requests — anyone can try the app's demo without an account. If you then ask us to contact you, we receive the shop name and email address you enter, the platform (iPhone, Android or web), the time, the exact consent text you ticked and a one-way hash of the IP address (used only to stop repeated submissions). Go Upstream AB is the controller.
- Technical data — basic logs needed to operate the service securely and diagnose errors.
3. How we use data
- To provide the app's core features: inventory management, sales overview and marketing.
- To display customer questions from Instagram comments to the shop, alongside the relevant item, and to let the shop reply (including an automatic "SÅLD"/"SOLD" reply when an item sells).
- To operate, secure and improve the service.
- To contact a shop that asked us to after trying the demo, by email and only about Helny, based on the consent given in the app. Reply "nej tack" (no thanks) or email us to withdraw it.
We do not sell personal data and we do not use it for advertising or profiling.
4. Instagram / Meta data
When a shop connects its Instagram Business account, Helny uses the Instagram Graph
API (Meta) to publish the shop's own items and to read and reply to comments on the
shop's own media. We request only the permissions needed for this
(instagram_business_basic, instagram_business_content_publish,
instagram_business_manage_comments).
- Comment data (text, username, timestamp) is used solely to show the shop the questions on its own posts and to post replies.
- It is accessed only for media owned by the connected account, shown only to the shop's own authenticated users, and is never shared with third parties or used for advertising.
- Access tokens are stored encrypted and can be revoked at any time by disconnecting Instagram in the app or removing the app at instagram.com/accounts/manage_access.
5. Service providers (sub-processors)
We share data only with the providers needed to run the service:
- Supabase — application database, authentication and file storage (EU, Stockholm).
- Vercel — hosting of a shop's public website and web shop (EU, Stockholm).
- Expo, with Apple (APNs) and Google (FCM) — push notifications.
- Resend — email delivery: login codes, newsletters, receipts and the reply to a demo contact request.
- 46elks — SMS delivery for pickup reminders (Sweden).
- Backblaze B2 — nightly backup of object photos (EU, Amsterdam).
- Google — image interpretation for the AI suggestions (name, description and category from an object photo), only when a shop uses that feature.
Services a shop connects with its own account — Zettle by PayPal, Fortnox, Meta (Instagram), TikTok, Tradera and Stripe — are governed by the shop's own agreement with that provider. We exchange data with them only for the integration the shop has switched on. Some providers above are established outside the EU/EEA; such processing relies on the EU standard contractual clauses or an adequacy decision.
6. Storage and security
Data is stored on infrastructure provided by Supabase and is protected by access controls and encryption in transit. Access to a shop's data is restricted to that shop's authenticated users. Our databases are hosted on servers located within the European Union, in Stockholm, Sweden (AWS region eu-north-1).
7. Retention and deletion
We keep data for as long as the shop uses the service. A shop can request export or deletion of its data, or deletion of a user account, by emailing us (section 9). We delete or anonymise a shop's data 90 days after its agreement ends, or earlier on a verified request. Encrypted backups are rotated out within a further 90 days.
A demo contact request is kept while we are in contact. If the shop does not become a customer, it is deleted automatically 12 months after our last contact, and at once if you withdraw your consent.
8. Your rights
Under the GDPR you may request access to, correction of, or deletion of your personal data, and object to or restrict certain processing. To exercise a right, contact us (section 9). You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
9. Contact & data deletion requests
Go Upstream AB
Email: hej@helny.app
To request deletion of your data, email the address above with the subject "Data deletion request" and the account or shop concerned. We will confirm and process the request.
10. Changes to this policy
We may update this policy as the service evolves. The "Last updated" date above reflects the latest version.