Back to sign in STK
Legal · STK

Privacy Policy

Effective 19 July 2026 Operator: STK · support@stk.now

This Privacy Policy explains how Stk collects, uses, stores, and protects personal data. It applies to merchants who use Stk and, where relevant, to the end customers of those merchants whose data flows into Stk through integrations such as Shopify.

1. Who this policy covers

  • Merchants — businesses and individuals who create a Stk account.
  • End customers — customers of merchants whose personal data (name, email, address, phone) reaches Stk via Shopify order webhooks or manual entry.

Stk has no direct relationship with end customers. Merchants are the data controllers; Stk acts as a data processor on the merchant’s behalf.

2. Data we collect

Category Fields Source Purpose
Merchant account Name, email, organisation name, role Registration Authentication, account management, support
Business data Products, inventory levels, warehouses, orders (no customer PII) Merchant input Core inventory management
Customer PII
Protected data
First name, last name, email, shipping address, billing address, phone Shopify order webhooks (orders/create, orders/cancelled) or manual entry Create Sales Orders; match/create customer contact records; order fulfilment on behalf of the merchant
Integration tokens Shopify OAuth token, Xero token, Starshipit API key OAuth / manual Authenticate API calls to connected services
Usage & logs API request/response logs, webhook delivery logs, error logs System-generated Debugging, security, audit trail
Analytics inputs & outputs Aggregated commerce, inventory, and advertising metrics; product, campaign, and ad labels; analysis prompts; generated reports Stk, enabled integrations, and authorised users Provide optional LLM-assisted analytics and retain report provenance

3. How we use personal data

We process personal data only to the extent necessary to provide the Stk service:

  • Merchant account data — authentication, account management, billing, support.
  • Customer PII from Shopify — to create and update Sales Orders and to match or create customer contact records. Direct customer identifiers are used for order and customer management on behalf of the merchant, not for Stk marketing or advertising, and are never sold.
  • Analytics data — when an authorised user requests LLM-assisted analytics, Stk derives and transmits selected aggregate metrics, business labels, analysis instructions, and prompts to the external LLM provider to generate a report. The analytics payload is designed to exclude raw orders and direct customer identifiers such as names, email addresses, phone numbers, and street addresses.
  • Integration tokens — to make authorised API calls on your behalf.
  • Logs — debugging, security monitoring, and audit purposes.

4. Lawful basis for processing

  • Contract performance — processing necessary to deliver the service you subscribed to.
  • Legitimate interests — security monitoring, fraud prevention, system reliability.
  • Legal obligation — retaining records where required by law.

5. Data sharing

We do not sell or rent personal data. We may share data with:

  • Shopify — inventory and product data pushed via Shopify Admin API as part of the sync service;
  • Xero — order and financial data when the Xero integration is active;
  • Starshipit — shipment data when the postage integration is active;
  • Hosting provider — production data is hosted on DigitalOcean infrastructure in Sydney, Australia; server-level data protection is in place;
  • External LLM provider — when LLM-assisted analytics is enabled and requested, selected aggregate metrics, business labels, and the analysis prompt are sent to DeepSeek to generate the requested report. DeepSeek is operated from, and states that it processes and stores data in, the People’s Republic of China. Its handling, retention, and any use of inputs or outputs for service improvement or model training are governed by its privacy policy and service terms. We may replace or add an LLM provider and will update this policy when that materially changes where or how relevant data is handled;
  • Legal authorities — if required by law, court order, or to protect the rights or safety of others.

6. Data retention

  • Merchant account and business data — retained for the lifetime of the account plus 30 days after termination.
  • Customer PII — retained as part of the Sales Order record while the account is active; deleted within 30 days of a verified deletion request.
  • API and webhook logs — retained for 90 days, then purged.
  • Analytics prompts, source snapshots, and generated reports — retained within Stk for report history, audit, and provenance while the relevant account or report record remains active, then deleted or de-identified in accordance with our account-deletion process. External providers apply their own retention and deletion rules.

7. Security

  • All data in transit encrypted via TLS/HTTPS;
  • Data at rest stored with server-level encryption;
  • Backups encrypted and stored separately from live data;
  • Strict multi-tenant isolation — each merchant’s data is isolated by OrganizationID;
  • Token-based authentication; passkey (WebAuthn) support available;
  • Security incident response policy in place; affected merchants notified of breaches as required by law.

No internet transmission, storage system, backup, or security control is completely secure. Although we take reasonable steps to protect data, we cannot guarantee that loss, unauthorised access, or a security incident will never occur.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data we hold, and to object to or restrict certain processing. Contact us at support@stk.now with subject line Privacy Request — [your organisation].

9. Shopify protected customer data

Stk may receive protected customer data (name, email, address, phone) from an authorised Shopify connection via Shopify order webhooks. Direct customer identifiers are used for store management, including order fulfilment and customer record matching, and are not sent to the LLM analytics provider. If analytics is enabled, Stk may derive aggregate or de-identified measures from Shopify order data, such as revenue, product-family performance, broad region, and repeat-customer counts using hashed customer keys.

Merchants connecting Shopify to Stk are responsible for ensuring their own privacy notices to customers disclose that order data may be shared with inventory management systems.

10. LLM-assisted analytics and your choices

LLM-assisted analytics is optional. Stk performs calculations and aggregation inside the Stk environment, then sends a limited analysis payload to an external LLM to interpret the data and generate recommendations. The LLM does not receive access to the Stk database. Generated output is probabilistic, is reviewed at the user’s discretion, and is not used by Stk to make automated decisions about an individual’s rights or interests.

Organisations that do not want analytics data or prompts sent to an external LLM service must not enable or use LLM-assisted analytics and should disable the analytics integration. Contact support@stk.now if immediate deactivation is required. Disabling the integration prevents future requests; it does not recall prior submissions or override an external provider’s retention obligations.

Editable prompts are transmitted as entered. Users must not include personal information, sensitive information, confidential third-party material, or regulated data in a prompt, product label, campaign name, or other free-text field intended for analysis.

11. Overseas processing

Stk’s primary production hosting is in Australia. Data may nevertheless be processed outside Australia when you enable or use an overseas integration or service. LLM-assisted analytics currently uses DeepSeek in the People’s Republic of China. Connected services may process data in other countries identified in their own privacy notices. Where the Australian Privacy Principles apply, we take reasonable steps required by law in relation to overseas recipients; describing overseas processing in this policy does not remove any responsibility that cannot lawfully be excluded.

12. Cookies and tracking

The Stk application uses a single authentication token stored in an HTTP-only cookie. No third-party tracking cookies, advertising pixels, or analytics scripts are loaded in the authenticated application.

13. Australian Privacy Act

Stk complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you believe we have breached the APPs, contact us first; unresolved complaints may be lodged with the Office of the Australian Information Commissioner (OAIC).

14. GDPR (EU/UK merchants)

EU and UK merchants have additional rights under GDPR / UK GDPR, including the right to lodge a complaint with your local supervisory authority. Contact us at support@stk.now to exercise GDPR rights.

15. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice. The effective date at the top reflects the most recent revision.

16. Contact

Email: support@stk.now
Subject: Privacy Request — [your organisation name]
Response time: We aim to respond within 5 business days.

The terms that govern your use of Stk are set out in a separate document.

See: Terms of Service


© 2026 STK · Stock. Taken care of.

Back to STK · Terms of Service · support@stk.now