SortNGo
How it worksFeaturesPricingSecurityWho it's for
Sign inStart free โ†’
Legal

Privacy Policy

Plain language. No surprises. We built our privacy architecture into the product itself โ€” this document just explains how.

๐Ÿ“… Last updated: May 2025โš–๏ธ Jurisdiction: Iceland๐Ÿข Operated by: SortNGo โ€” sortngo.com
๐Ÿ”’

The short version, if that's all you have time for

Your uploaded files are processed entirely in your browser. The raw content never reaches our servers. We store your account details and your client roster. Job results and outputs from any opt-in Tools features are only stored on our servers if you have explicitly chosen to enable those features โ€” by default, nothing beyond your account and roster is stored. We don't sell your data. We don't use it to train AI models. You can delete everything at any time.

Contents
1Who we are2What we collect3What we do NOT collect4How we use your data5Third-party processors6Cookies & local storage7Data retention8Your rights (GDPR)9Security10Children11Changes to this policy12Contact us
01

Who we are

SortNGo is a data sorting and private distribution platform operated at sortngo.com. The service is run by an individual operator based in Iceland. For any data protection matters, we are the data controller.

Iceland is a member of the European Economic Area (EEA). The General Data Protection Regulation (GDPR) therefore applies in full to how we handle personal data. Where this policy refers to "GDPR rights", that means your rights under Regulation (EU) 2016/679 as incorporated into Icelandic law.

Contact for all data and privacy matters: hello@sortngo.com

02

What we collect

We collect only what is strictly necessary to provide the service. The table below sets out each category of data, why we collect it, and the legal basis we rely on under GDPR.

DataWhy we collect itLegal basisStored
Email addressAccount creation, login, password reset, service emailsContract performanceYes
Display namePersonalisation within the app (optional)Legitimate interestYes
Password (hashed)AuthenticationContract performanceYes
Client roster dataThe contact and identifier data you enter for your own clients โ€” this is what the sorting engine matches againstContract performanceYes
Job results (match results)Sorted outputs saved to job history for your future reference โ€” only collected and stored if you have explicitly enabled the Job History featureContract performanceYes
Opt-in Tools dataData generated by optional Tools features (such as notification certificates or acknowledgement logs) โ€” only stored if you have explicitly activated that specific ToolContract performanceOnly when activated
Column mapping templatesSaved supplier file formats so you don't have to remap every timeContract performanceYes
Usage eventsAnonymised activity signals (login timestamps, job run counts) used for aggregate analytics onlyLegitimate interestYes
Email preferencesWhether you have opted in to announcements or tips emailsConsentYes

Data you enter about third parties (your clients)

When you build your client roster in SortNGo, you may enter personal data about your own clients โ€” names, email addresses, phone numbers, and similar. You are the data controller for that data. SortNGo acts as a data processor on your behalf. You are responsible for ensuring you have a lawful basis to store that data in SortNGo and that doing so complies with any obligations you have to those individuals.

03

What we do not collect

โœ…

Your uploaded file content never reaches our servers

This is the core architectural guarantee of SortNGo. When you upload an Excel or CSV file, or paste data directly, it is parsed entirely inside your browser using JavaScript. The raw file content โ€” every row, every cell โ€” is processed locally on your device and is never transmitted to or stored on SortNGo's servers. Only the sorted match results are saved.

Specifically, we do not collect or store:

  • The content of any Excel or CSV files you upload
  • Raw pasted data you enter into the paste mode input
  • Any data from rows that did not match your client roster (orphaned rows)
  • Payment card details or banking information of any kind
  • Device fingerprints, browser identifiers, or advertising IDs
  • Location data

No advertising. No AI training.

SortNGo does not display advertising. We do not sell your data to third parties. We do not use your data โ€” or any data processed through the service โ€” to train machine learning models, large language models, or any other AI systems.

04

How we use your data

We use the data we hold for the following purposes only:

  • Providing the service โ€” operating your account, running the sorting engine, saving your job history and client roster.
  • Authentication โ€” verifying your identity when you log in and when you reset your password.
  • Service communications โ€” sending you transactional emails (email confirmation, password reset, significant changes to the service). These are not optional while you hold an account.
  • Optional communications โ€” sending product updates, tips, or announcements, only if you have opted in. You can opt out at any time in your profile settings.
  • Aggregate analytics โ€” understanding how the service is used in aggregate (e.g., daily active users, total jobs run) to guide development priorities. This analysis does not involve examining individual user data.
  • Abuse prevention โ€” detecting and preventing misuse of the platform.
๐Ÿ“ง

About our email system

SortNGo uses its own SMTP infrastructure to send service emails from hello@sortngo.com. Your email address is used solely to deliver emails you would reasonably expect to receive as an account holder. We do not share your email address with any third-party marketing platform.

05

Third-party processors

We use a small number of third-party service providers to operate the platform. Each is listed below with details of what data they handle and why.

ProviderPurposeData processedLocation
SupabaseDatabase, authentication, row-level securityAccount data, client roster, job results, usage eventsEU (AWS)
Vefgeymslan.isWeb hosting / server infrastructureApplication code; no user data stored directlyIceland
Stackmail / SMTP hostingTransactional email deliveryYour email address, email content of messages we send youEU

We do not engage any advertising networks, analytics platforms (such as Google Analytics), social media trackers, or data brokers. We do not share your personal data with any third party for their own marketing or commercial purposes.

Supabase and data location

Your account data and client roster are stored in Supabase, which runs on Amazon Web Services infrastructure within the European Union. Supabase operates as a data processor under a Data Processing Agreement. All data remains within the EEA. For more information, see Supabase's privacy policy.

06

Cookies & local storage

SortNGo uses a minimal set of cookies and browser storage. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

What we use

  • Authentication session cookie โ€” set by Supabase to keep you logged in. Essential for the service to function. Expires when you log out or after your session times out.
  • localStorage (email template) โ€” your custom email template is saved locally in your browser's localStorage so it persists between sessions. This data never leaves your device. You can clear it at any time by clearing your browser storage.

What we do not use

  • No advertising or tracking cookies of any kind
  • No third-party analytics cookies (e.g. Google Analytics)
  • No social media tracking pixels

Because we use only essential cookies, we do not display a cookie consent banner. If we ever add non-essential cookies, we will update this policy and implement appropriate consent mechanisms before doing so.

07

Data retention

We keep your data for as long as your account is active. If you delete your account, we will delete your personal data โ€” including your email address, display name, client roster, and all job history โ€” within 30 days of your deletion request.

Job results and any data generated by opt-in Tools features are retained for as long as you keep them and the relevant feature remains enabled. You can delete individual job records from your job history at any time, or disable Job History entirely to stop new results from being stored. The same applies to any future opt-in Tools: disabling a Tool stops new data from being stored, and any stored data for that Tool can be deleted from within the Tool itself.

Some anonymised aggregate usage statistics (such as total jobs run in a given month) may be retained for internal analytics after account deletion, as these do not constitute personal data.

We do not retain data beyond what is reasonably necessary to operate the service, resolve disputes, or comply with legal obligations.

โš ๏ธ

Your file data is never retained

Because your uploaded file content is processed entirely in your browser and never sent to our servers, there is nothing for us to retain or delete regarding the raw content of your files. This is by design, not policy โ€” it is an architectural guarantee.

08

Your rights under GDPR

As a resident of the EEA or a user whose data we process, you have the following rights. You can exercise most of these directly from your account settings. For anything else, contact us at hello@sortngo.com.

๐Ÿ‘๏ธ

Right of access

You can request a copy of all personal data we hold about you at any time.

โœ๏ธ

Right to rectification

If any data we hold about you is inaccurate, you can correct it โ€” most of this you can do directly in your profile settings.

๐Ÿ—‘๏ธ

Right to erasure

You can delete your account and all associated personal data at any time from the Danger Zone in your profile settings. No need to contact us first.

๐Ÿ“ฆ

Right to portability

You can request your personal data in a structured, machine-readable format. Contact us at hello@sortngo.com and we will provide it within 30 days.

๐Ÿšซ

Right to object

You can object to processing based on legitimate interest. You can also opt out of non-essential emails at any time in your profile settings.

โš–๏ธ

Right to lodge a complaint

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Icelandic Data Protection Authority (Persรณnuvernd) at personuvernd.is.

We will respond to all data rights requests within 30 days. We will never charge a fee for reasonable requests.

09

Security

We take reasonable technical and organisational measures to protect your personal data. These include:

  • Row-level security (RLS) enforced at the database level โ€” no user can access another user's data, including us in normal operations
  • Passwords are hashed using industry-standard algorithms via Supabase Auth โ€” we never store plain-text passwords
  • All data in transit is encrypted using TLS
  • All data at rest is encrypted by Supabase on AWS infrastructure
  • Client-side file processing means your raw file data never traverses the network at all

No system connected to the internet can be perfectly secure โ€” and we will not pretend otherwise. We implement the measures described above and take security seriously, but we cannot guarantee, and do not promise, that your stored data will never be exposed through a breach, a vulnerability in our infrastructure, in third-party services we depend on, or by other means outside our direct control. This is an honest statement about the nature of internet-connected systems, not a disclaimer of responsibility โ€” it reflects the reality that absolute security can only exist in an air-gapped environment with no external connectivity. What we commit to is: acting reasonably and diligently, notifying you promptly if we become aware of a breach affecting your data, and continuously working to reduce risk. If you discover a security vulnerability, please contact us responsibly at hello@sortngo.com before disclosing it publicly.

10

Children

SortNGo is a professional data management tool intended for use by adults. The service is not directed at or intended for use by children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us at hello@sortngo.com and we will delete the account promptly.

11

Changes to this policy

We may update this Privacy Policy from time to time as the service evolves. If we make a material change โ€” one that meaningfully affects how we collect, use, or share your personal data โ€” we will notify you by email and post a notice in the app before the change takes effect.

For minor changes (correcting typos, clarifying existing language), we will update the "Last updated" date at the top of this page without issuing a separate notification.

Continued use of the service after a material change takes effect constitutes your acceptance of the updated policy. If you do not agree with a change, you may delete your account before the effective date.

12

Contact us

For any questions, data rights requests, or concerns about this Privacy Policy, please contact us. We aim to respond within 5 business days and are legally required to respond to GDPR-related requests within 30 days.

Get in touch

Privacy questions, data requests, security disclosures โ€” we read every email.

hello@sortngo.com

SortNGo โ€” sortngo.com โ€” Iceland ๐Ÿ‡ฎ๐Ÿ‡ธ

SortNGo

ยฉ 2026 SortNGo. Crafted with care in Iceland ๐Ÿ‡ฎ๐Ÿ‡ธ

PricingPrivacy PolicyAPITerms of ServiceWhat's NewContact