This Privacy Policy explains how Stk collects, uses, stores, and protects personal data. It applies to merchants who use Stk and, where relevant, to the end customers of those merchants whose data flows into Stk through integrations such as Shopify.
Stk has no direct relationship with end customers. Merchants are the data controllers; Stk acts as a data processor on the merchant’s behalf.
| Category | Fields | Source | Purpose |
|---|---|---|---|
| Merchant account | Name, email, organisation name, role | Registration | Authentication, account management, support |
| Business data | Products, inventory levels, warehouses, orders (no customer PII) | Merchant input | Core inventory management |
|
Customer PII Protected data |
First name, last name, email, shipping address, billing address, phone | Shopify order webhooks (orders/create, orders/cancelled) or manual entry |
Create Sales Orders; match/create customer contact records; order fulfilment on behalf of the merchant |
| Integration tokens | Shopify OAuth token, Xero token, Starshipit API key | OAuth / manual | Authenticate API calls to connected services |
| Usage & logs | API request/response logs, webhook delivery logs, error logs | System-generated | Debugging, security, audit trail |
| Analytics inputs & outputs | Aggregated commerce, inventory, and advertising metrics; product, campaign, and ad labels; analysis prompts; generated reports | Stk, enabled integrations, and authorised users | Provide optional LLM-assisted analytics and retain report provenance |
We process personal data only to the extent necessary to provide the Stk service:
We do not sell or rent personal data. We may share data with:
OrganizationID;No internet transmission, storage system, backup, or security control is completely secure. Although we take reasonable steps to protect data, we cannot guarantee that loss, unauthorised access, or a security incident will never occur.
Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data we hold, and to object to or restrict certain processing. Contact us at support@stk.now with subject line Privacy Request — [your organisation].
Stk may receive protected customer data (name, email, address, phone) from an authorised Shopify connection via Shopify order webhooks. Direct customer identifiers are used for store management, including order fulfilment and customer record matching, and are not sent to the LLM analytics provider. If analytics is enabled, Stk may derive aggregate or de-identified measures from Shopify order data, such as revenue, product-family performance, broad region, and repeat-customer counts using hashed customer keys.
Merchants connecting Shopify to Stk are responsible for ensuring their own privacy notices to customers disclose that order data may be shared with inventory management systems.
LLM-assisted analytics is optional. Stk performs calculations and aggregation inside the Stk environment, then sends a limited analysis payload to an external LLM to interpret the data and generate recommendations. The LLM does not receive access to the Stk database. Generated output is probabilistic, is reviewed at the user’s discretion, and is not used by Stk to make automated decisions about an individual’s rights or interests.
Organisations that do not want analytics data or prompts sent to an external LLM service must not enable or use LLM-assisted analytics and should disable the analytics integration. Contact support@stk.now if immediate deactivation is required. Disabling the integration prevents future requests; it does not recall prior submissions or override an external provider’s retention obligations.
Editable prompts are transmitted as entered. Users must not include personal information, sensitive information, confidential third-party material, or regulated data in a prompt, product label, campaign name, or other free-text field intended for analysis.
Stk’s primary production hosting is in Australia. Data may nevertheless be processed outside Australia when you enable or use an overseas integration or service. LLM-assisted analytics currently uses DeepSeek in the People’s Republic of China. Connected services may process data in other countries identified in their own privacy notices. Where the Australian Privacy Principles apply, we take reasonable steps required by law in relation to overseas recipients; describing overseas processing in this policy does not remove any responsibility that cannot lawfully be excluded.
The Stk application uses a single authentication token stored in an HTTP-only cookie. No third-party tracking cookies, advertising pixels, or analytics scripts are loaded in the authenticated application.
Stk complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. If you believe we have breached the APPs, contact us first; unresolved complaints may be lodged with the Office of the Australian Information Commissioner (OAIC).
EU and UK merchants have additional rights under GDPR / UK GDPR, including the right to lodge a complaint with your local supervisory authority. Contact us at support@stk.now to exercise GDPR rights.
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice. The effective date at the top reflects the most recent revision.
Email: support@stk.now
Subject: Privacy Request — [your organisation name]
Response time: We aim to respond within 5 business days.
The terms that govern your use of Stk are set out in a separate document.
See: Terms of Service
© 2026 STK · Stock. Taken care of.