Ship governed store, supplier and compliance workflows beside your merchandise management, not inside it
For multi-store retailers, specialist and wholesale traders, retail cooperatives and franchise networks, and omnichannel brands: build supplier onboarding, product and packaging compliance, store operations, claims and rebate reconciliation as production software with review points, traceability and code ownership.
Modernise around ERP, POS, PIM, shop system and supplier portals while the merchandise management migration runs. Nothing we build lands in the core system change backlog.
Where it runs
Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU, or your own cloud (BYOC) and on-premise on Enterprise.
What it connects to
Merchandise management and ERP (SAP Retail and S/4HANA, Microsoft Dynamics 365, and others), POS exports, PIM, shop systems (Shopware, Shopify, Magento), OMS and supplier portals via APIs, exports and database views.
What we do not touch
The checkout, payment, the merchandise management itself and the EDI messages your ERP already exchanges. Those stay where they are.
Who owns the code
You do. Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database. Export it at any time.
What retail teams evaluate first
These are the questions the head of operations, the IT lead, the compliance officer and the works council ask before a pilot gets a budget line.
Hosting in Germany
Nuclicore-managed on Hetzner in Germany or Azure in the EU, with BYOC or on-premise on Enterprise. No data leaves the EU unless you decide otherwise.
Beside the merchandise management, not inside it
Every workflow runs as a side-by-side application against ERP, POS and PIM interfaces. Your migration keeps its scope, its freeze and its cutover date.
Written for the works council
Roles per store, region and head office. No employee-level performance data unless you decide to include it, and the access concept is documented so the works council can sign it off.
Audit trail for market surveillance and marketplaces
Who raised, who reviewed, who approved, when, with what evidence. Exportable per product, supplier or case when the authority, the marketplace or the auditor asks.
Supplier access without supplier risk
Suppliers upload declarations, test reports and packaging evidence in their own portal role. They see their products and nothing else.
Evidence for security questionnaires
Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app. Release gates and logs give you documented technical measures for marketplace, payment and insurer questionnaires.
Exit without a rewrite
Standard code, standard database, documented interfaces. Procurement gets an exit path before signature, not after.
Built for real retail operating models
Align scope, workflow ownership and governance for the segment you operate in.
Multi-store retail chains
- Store requests and incidents in one queue instead of the phone
- Price and markdown changes approved before they hit the shelf
- Store audits with photos and follow-up actions per branch
- Head office to store request and incident handling
- Price change and markdown approvals
- Store audits and checklists
Specialist retail and wholesale
- Supplier compliance dossiers complete before listing
- Customer claims with supplier recourse tracked to settlement
- Rebates and conditions reconciled with evidence per supplier
- Supplier onboarding and product compliance
- Claims and warranty with supplier recourse
- Rebate and condition reconciliation
Retail cooperatives and franchise networks
- One codebase, one release per member, brand or region
- Central standards with member-specific approvers
- Compliance evidence shared between head office and members
- Central to member approval workflows
- Marketing allowance and campaign approvals
- Shared supplier and product compliance registers
Omnichannel and private label brands
- Product data complete for GPSR, PPWR and the product passport
- Private label releases with the manufacturer obligations checked
- Returns dispositions decided by rule, exceptions by a person
- Product compliance data collection
- Private label product release
- Returns disposition and refund approvals
Why delivery models are changing in retail
The retailers that ship fastest keep the merchandise system standard, move exceptions out of mail and treat compliance as running software.
Common Reality
Product data is now compliance evidence
GPSR since December 2024, the packaging regulation since August 2026, the battery passport from February 2027, textiles expected around 2028. Each one asks for evidence per product and per supplier, and private label makes the retailer the manufacturer.
Common Reality
The store network runs on mail, phone and messenger groups
Price changes, incidents, maintenance, audits and stock questions travel between head office and stores through channels nobody can search. It works until a district manager leaves or a market surveillance request arrives.
Common Reality
IT is the merchandise management project until 2027
The ERP migration takes 12 to 24 months and comes with a customisation freeze. Every request from operations, purchasing or compliance that is not part of the migration waits.
What you can build across suppliers, stores and finance
Deliver governed software around your systems of record, with review points, traceability and code ownership.
Suppliers and product compliance
Supplier onboarding and compliance dossier
Suppliers submit declarations of conformity, test reports, GPSR data, responsible person and safety information per product in a portal; purchasing and compliance review and approve before listing.
- Supplier portal role
- Document expiry
- Approval before listing
Packaging compliance register
Material composition, recyclability evidence and supplier declarations per packaging, EPR registration and volume reporting per country, with the evidence file ready for authority and marketplace requests.
- Per packaging item
- Per country EPR
- Export on request
Private label product release
Release checklist for own-brand products covering manufacturer obligations, labelling, documentation and the responsible person, with sign-off by purchasing, quality and legal.
- Release checklist
- Three-party sign-off
- Version per product
Product passport data collection
Collect the attributes per product group from suppliers in a structured form, validate completeness, and hand the data to your PIM or passport provider with a record of who supplied what.
- Structured collection
- Completeness check
- PIM handover
Stores and network operations
Store requests and incident handling
Stores raise requests and incidents on a tablet or phone, head office routes and prioritises, the store sees the status, and every case has an owner and a closure.
- Mobile-first forms
- Routing rules
- Status per store
Price change and markdown approvals
Proposed changes with reason and impact, approval thresholds per category and region, and a record of who approved what before it reaches the POS.
- Approval thresholds
- Per region
- Write-back to ERP
Store audits and checklists
Versioned audit checklists completed on the device with photos, findings routed as actions to the store or facility team, history per branch.
- Versioned checklists
- Photo evidence
- Actions per branch
Maintenance and repair requests
Store raises the request, facility management prioritises, contractor executes and closes with evidence, cost recorded against the branch and the asset.
- Contractor role
- Cost per branch
- Asset history
Customers, finance and conditions
Customer claim intake, assessment, decision, and the recourse case against the supplier tracked to settlement with deadlines and evidence.
- Deadline tracking
- Supplier recourse
- Settlement record
Rule-based disposition for standard returns, exception approval for high-value or damaged items, refund approval above thresholds, and the record per return.
- Rule-based routing
- Refund thresholds
- Record per return
Rebate and condition reconciliation
Agreed conditions per supplier, actual volumes from the ERP, calculated rebates, disputes with evidence and the approval before the credit note.
- Conditions per supplier
- Dispute workflow
- Credit note approval
Supplier-funded campaigns and allowances requested, approved, executed and proven with evidence, so the claim to the supplier is complete.
- Request to approval
- Evidence of execution
- Claim record
Fits your systems of record
Most ROI comes from removing manual handoffs between purchasing, compliance, stores, customer service and finance, and from connecting to the merchandise management with clear ownership of every interface.
We build governed workflows around ERP, POS, PIM, shop system, OMS, supplier portals and document management. We read what these systems expose and write back through their supported interfaces. We do not touch checkout, payment or the merchandise management itself.
What we need from you
- Interface specs or sandbox access for the ERP or merchandise management (APIs, exports or database views)
- Sample exports from POS, PIM or the shop system
- One named owner per workflow on the business side and one on the IT side
- The approval matrix: who may approve what, per store, region and value
Integration patterns supported
- APIs and exports of your ERP, PIM and shop system
- File exchange via SFTP (CSV, XML and the formats your suppliers and marketplaces already send) with validation and error queue
- Read-only database views and scheduled extracts from POS and OMS
- Webhooks and events for status changes into ERP, ticketing and mail
- Document handover to DMS and archive systems with retention metadata
Governed releases, stable production
- Scope is clarified and acceptance criteria are defined before implementation.
- Every change is a task with a reviewer, a preview and an approval record.
- Releases move through Preview, Test and Production, and any earlier release can be redeployed from the history.
- Store, region and member-specific configuration is data, not code, so one release serves the whole network.
- Supplier and store roles are scoped per case and per field, and documented for the works council.
- Audit trail per product, supplier and case, exportable for authorities, marketplaces and internal audit.
Security and data controls for retail
Each application runs its own backend, with a managed, encrypted Postgres per environment. Single-tenant infrastructure, BYOC and on-premise on Enterprise. Hosting in Germany or the EU by default.
RBAC, audit logs and monitoring keep access controlled per store, region, role and supplier. Dependency scanning, secrets handling, CVE patching and a nightly ZAP scan run on every app, which gives you documented technical measures for marketplace, payment and insurer questionnaires. Your workspace content is not used to train models.
Security controls in practice
- Own backend per application, managed Postgres per environment with each application on its own table suffix, dedicated or single tenant databases on Enterprise.
- RBAC with store, region, role and supplier scopes; SSO on Enterprise
- Audit log of every write action and sensitive read, exportable
- Dependency scanning, CVE patching and nightly ZAP scan on every app
- Supplier and store portal roles see only their own cases and fields
What a first retail pilot looks like
We align on one approval-heavy workflow and deliver reviewable increments with clear governance.
Scope, acceptance criteria, architecture outline
Pick one workflow (for example supplier compliance dossiers, store incident handling or rebate reconciliation). Define roles, approval matrix, the ERP fields to read and the records to write back.
First working version in Preview
Forms, routing, approvals and the read integration to your ERP, PIM or POS exports. Purchasing, store and compliance users click through and comment in the task.
Test environment with real roles and real data
Store, region and supplier roles, SSO if applicable, write-back to ERP or DMS, audit trail export. Your IT and the works council review the interface and the access concept.
Production release and handover
Approval, release to Production, redeploy of an earlier version verified. Documentation for IT, operations and the works council. Decision on the next workflow.
Success criteria examples
- Every case in the pilot workflow closed with a complete approval chain, no mail threads
- Audit trail export accepted by compliance or internal audit
- ERP interface documented and signed off by the system owner
- Access concept signed off by the works council
Retail & Wholesale FAQ
Answers for operations, purchasing, compliance and IT.
What does "governed" mean for retail workflows?
Work is organised into reviewable tasks with acceptance criteria. Releases move through Preview, Test and Production with approval, and any earlier release can be redeployed. Every case carries who raised, reviewed and approved it, with timestamps and evidence. That is the trail authorities, marketplaces and auditors ask for.
Our ERP has a supplier portal. Why build beside it?
Because the portal covers master data and orders, and the compliance dossier leaves it: the test report that expires, the responsible person that changes, the packaging evidence the marketplace asks for. Nuclicore builds the workflow around the portal and writes the result back, so the ERP stays the system of record.
Do you touch the POS or the checkout?
No. Checkout, payment and the POS stay as they are. Apps read POS exports where a workflow needs them and hand approved changes to the ERP through its supported interface.
We are a cooperative with independent members. One app or one per member?
One app, one codebase, one release. Member, brand and region-specific fields, approvers and thresholds are configuration, not code. Deployment labels let you release per member or legal entity when a member needs a different cutover date.
How do you handle the works council?
Roles are scoped per store, region and head office, no employee-level performance data is included unless you decide to include it, and the access concept is documented so the works council can sign it off before the pilot goes to production.
We sell private label. Does this cover our manufacturer obligations?
It covers the process side: release checklists, documentation, responsible person, packaging evidence and product passport data collection with sign-off and audit trail. The legal assessment of which obligations apply to which product remains with your compliance team.
Can it run on-premise or in our own tenant?
Yes. BYOC and on-premise deployment are available on Enterprise. The default is Nuclicore-managed single tenant on Hetzner in Germany or Azure in the EU.
We ship to several EU countries. Does the packaging register handle that?
Yes. EPR registrations, volume reporting periods and evidence are kept per country, with the responsible person per country on record. The registration with each national scheme remains yours; the app keeps the evidence and the deadlines.
Who owns the code and the data?
You do. Each app is a standard React and Node repository with its own backend, running on a managed, encrypted Postgres database. You can export the code and the data at any time and run it yourself. Procurement gets the exit path before signature.
Who maintains the app after the pilot?
Your team, through the same platform: describe the change, review the task, approve the release. Security patches to dependencies are applied by the platform. If you want to take the code and maintain it in-house, you can.
What is not a fit?
Checkout and payment, the merchandise management itself, the shop system, demand forecasting and replacing the PIM. Nuclicore builds the governed workflows around these systems, not the systems.
Move supplier, store and compliance workflows out of mail and into governed software.
Ship beside your merchandise management, works-council-ready, with audit trail and code you own.