Privacy policy
Effective 1 September 2026
This policy explains how Stoxa Limited (“Stoxa”, “we”, “us”) handles personal data when a business and its authorised team members use the Stoxa inventory service, mobile app and web app. Stoxa is designed for business use and is not a consumer or family service.
1. Information we handle
Depending on how your organisation uses Stoxa, we may handle:
- account information such as name, business email address, role, organisation and authentication identifiers;
- business inventory information including products, SKUs, batches, barcodes, quantities, locations, product photographs and stock movements;
- customer and transaction information entered by your organisation, including contact, billing, sales and tax information;
- subscription information such as plan, allowance, App Store or Google Play purchase identifiers, payment status and renewal dates;
- integration information needed to connect optional services such as Xero;
- security, session and technical information needed to protect accounts, diagnose failures and operate the service;
- support correspondence you send to us.
Stoxa does not sell personal data, serve behavioural advertising or use personal data for cross-app tracking. Payments are handled by Apple or Google; Stoxa does not receive or store full card numbers.
2. How we use information
- to provide inventory, scanning, reporting, team, billing and integration functions;
- to authenticate users and enforce organisation roles and permissions;
- to process and administer the organisation’s subscription;
- to secure, maintain, troubleshoot and improve Stoxa;
- to provide support and important service communications;
- to comply with legal, tax and regulatory obligations.
For UK data-protection purposes, processing is normally necessary to perform our contract with the customer organisation, pursue legitimate interests in operating and securing the service, comply with law, or act on consent where consent is the appropriate basis.
3. Business customer responsibilities
The customer organisation controls the business records its users enter into Stoxa. It is responsible for having a lawful basis to enter customer, employee and transaction data, deciding who receives access, and responding to relevant data-subject requests. Stoxa processes that information to provide the service on the organisation’s instructions.
4. Service providers and integrations
We use carefully selected providers to operate Stoxa, including Google Firebase for authentication, database, file storage and server functions; Apple and Google Play for app distribution and subscription billing; Resend for account emails; and Xero when an organisation chooses to connect its Xero account. These providers process only the information needed for their services and may retain records where required by law.
5. Device permissions and local data
The app requests camera access for barcode and QR scanning and for taking a product photograph. Photo-library access is used only when you choose an existing image. Product images are cropped and compressed before upload. The app may store preferences and recoverable stock-trolley drafts locally on the device, including while offline. Offline drafts are synchronised when connectivity returns and are removed under Stoxa’s draft-retention policy.
6. Retention and deletion
We retain organisation data while the customer account is active and as reasonably necessary to provide the service. A team member can delete their own account from Settings; business records that form part of the organisation’s audit and transaction history remain available to authorised business members. The business owner can delete the entire business from Settings, which removes its Stoxa organisation data, product photographs and team accounts. Deleting Stoxa data does not automatically cancel a subscription held by an App Store or Google Play account; the owner must cancel it in that store’s subscription settings.
Backups and security records may take a limited period to expire. Apple, Google Play, Xero and other independent providers may retain transaction or accounting records under their own legal obligations. We may retain limited records where law requires it or where necessary to establish, exercise or defend legal claims.
7. Security and international processing
We use role-based access, authenticated server operations, encryption in transit and service-provider security controls. No system is completely secure, but we continually take proportionate measures appropriate to the nature of the service. Providers may process data outside the United Kingdom under recognised contractual or legal safeguards.
8. Your rights
Depending on applicable law, individuals may have rights to access, correct, erase, restrict or object to processing, obtain a portable copy, or complain to the UK Information Commissioner’s Office. Business users should normally contact their organisation first because it controls the business records entered into Stoxa. You may also contact us directly.
9. Children
Stoxa is a business inventory service and is not intended for children.
10. Changes
We may update this policy as Stoxa or the law changes. We will publish the revised date here and provide additional notice where a change materially affects users.