Helny.app Home

Helny — Privacy Policy

Provided by Go Upstream AB · Last updated: 3 October 2026

Helny is a business management application for antique and second-hand shops, developed and operated by Go Upstream AB ("we", "us"). This policy explains what personal data the app processes, why, and the choices you have. It applies to the Helny app and its connected services.

1. Who is responsible for your data

Helny is used by antique/second-hand shops to manage their inventory, sales and marketing. For the business data that a shop enters and for data from the shop's own connected accounts (such as its Instagram Business account), the shop is the data controller and Go Upstream AB acts as a data processor on the shop's behalf. For the operation of the app itself and its user accounts, Go Upstream AB is the controller.

2. Data we process

3. How we use data

We do not sell personal data and we do not use it for advertising or profiling.

4. Instagram / Meta data

When a shop connects its Instagram Business account, Helny uses the Instagram Graph API (Meta) to publish the shop's own items and to read and reply to comments on the shop's own media. We request only the permissions needed for this (instagram_business_basic, instagram_business_content_publish, instagram_business_manage_comments).

5. Service providers (sub-processors)

We share data only with the providers needed to run the service:

Services a shop connects with its own account — Zettle by PayPal, Fortnox, Meta (Instagram), TikTok, Tradera and Stripe — are governed by the shop's own agreement with that provider. We exchange data with them only for the integration the shop has switched on. Some providers above are established outside the EU/EEA; such processing relies on the EU standard contractual clauses or an adequacy decision.

6. Storage and security

Data is stored on infrastructure provided by Supabase and is protected by access controls and encryption in transit. Access to a shop's data is restricted to that shop's authenticated users. Our databases are hosted on servers located within the European Union, in Stockholm, Sweden (AWS region eu-north-1).

7. Retention and deletion

We keep data for as long as the shop uses the service. A shop can request export or deletion of its data, or deletion of a user account, by emailing us (section 9). We delete or anonymise a shop's data 90 days after its agreement ends, or earlier on a verified request. Encrypted backups are rotated out within a further 90 days.

A demo contact request is kept while we are in contact. If the shop does not become a customer, it is deleted automatically 12 months after our last contact, and at once if you withdraw your consent.

8. Your rights

Under the GDPR you may request access to, correction of, or deletion of your personal data, and object to or restrict certain processing. To exercise a right, contact us (section 9). You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

9. Contact & data deletion requests

Go Upstream AB
Email: hej@helny.app

To request deletion of your data, email the address above with the subject "Data deletion request" and the account or shop concerned. We will confirm and process the request.

10. Changes to this policy

We may update this policy as the service evolves. The "Last updated" date above reflects the latest version.