Privacy Policy
Last updated: September 2026
This policy explains what personal data stockvpro collects, why we collect it, how long we keep it, and the rights you have over it. It covers our public website and the stockvpro application.
Who we are
stockvpro is inventory, warehouse and order management software for small businesses. For data you enter into the application, we act as a processor on behalf of the organisation whose workspace you belong to; that organisation is the controller of its own business data. For account and website data described below, we act as the controller.
Questions about this policy or your data: raise a request through the support section of your workspace, and it reaches us directly. If you cannot sign in, ask an administrator of your organisation to raise it for you.
What we collect
| Data | Why we hold it | Legal basis |
|---|---|---|
| Name, email address, optional phone number | To create and identify your account, sign you in, and contact you about the service. | Contract |
| Password (stored only as a salted hash — never in readable form) | To authenticate you securely. | Contract |
| Two-factor authentication secret, if you enable 2FA | To verify your one-time codes at sign-in. | Contract |
| Role, permissions and organisation membership | To show you the right data and enforce access control. | Contract |
| Sign-in timestamps, activity log entries and the IP address of an action | Security, abuse and rate-limit protection, and an audit trail for your organisation's administrators. | Legitimate interests |
| Business data you enter — products, stock, warehouses, stores, transfers, orders, customer and supplier contact details, support tickets | To provide the service to your organisation. We process it on that organisation's instructions. | Contract |
| Cookie preferences | To remember your choice so we don't ask on every visit. | Legal obligation / consent |
We do not collect special-category data, we do not build advertising profiles, and we never sell personal data.
Customer portal users
If an organisation invites you to its customer ordering portal, we hold your name, email address, a password hash, and the orders you place, so that the portal can authenticate you and show your order history. That organisation controls this data.
How we use it
- To provide, maintain and secure the service.
- To authenticate you and enforce role-based access to your organisation's data.
- To send transactional messages — invitations, password resets, low-stock and order notifications.
- To detect, investigate and block abuse, including failed-login rate limiting.
- To diagnose faults and improve reliability and performance.
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not send marketing email without your consent.
Cookies
We use strictly necessary cookies to keep you signed in and to remember your cookie choice. Optional analytics and marketing cookies are off unless you turn them on. Full detail is in our Cookie Policy, and you can change your choice at any time using cookie settings.
Who we share it with
We share personal data only where it is needed to run the service:
- Other members of your organisation — colleagues in your workspace see your name and the actions you take, according to their role.
- Our hosting provider — the servers on which the application and database run.
- Our email provider — to deliver transactional email such as invitations and password resets.
- Authorities — where we are legally required to disclose data.
These providers act on our instructions under contract. We do not sell or rent personal data, and we do not share it with advertisers.
Where your data is stored
Data is stored on servers in the European Union. Where a provider processes data outside the EU/EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses.
How long we keep it
- Account data — for as long as your account is active. When your organisation's account is deleted, its users and business data are deleted with it.
- Activity log and audit entries — retained while the organisation exists, so that administrators keep a usable audit trail.
- Failed-login records — kept only as long as needed for rate limiting, then cleared.
- Session records — removed when the session expires or you sign out.
- Password reset tokens — short-lived, and invalidated once used.
- Backups — held on a rolling schedule and overwritten in turn.
How we protect it
- All traffic is served over HTTPS.
- Passwords are stored only as salted hashes; sensitive stored secrets are encrypted at rest.
- Optional two-factor authentication on user accounts.
- Every query is scoped to your organisation, so one workspace cannot read another's data.
- Role and permission checks on both the interface and the API.
- Rate limiting and lockout on repeated failed sign-in attempts.
No system can promise perfect security, but we work to keep these measures current.
Your rights
Subject to local law — and in the EU/EEA under the GDPR — you may ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct data that is wrong or incomplete — most profile fields you can edit yourself.
- Delete your data, where we have no overriding obligation to keep it.
- Restrict or object to processing based on legitimate interests.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, where processing relies on consent.
Raise a request through the support section of your workspace and we will respond within one month. If your data was entered into an organisation's workspace, we may need to refer your request to that organisation as the controller. You also have the right to complain to your local data protection authority.
Children
stockvpro is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, tell us using the contact route above and we will delete it.
Changes to this policy
We may update this policy from time to time. Changes are posted on this page with a revised "last updated" date; where a change materially affects you, we will notify you in the application or by email.