Stocked

Privacy Policy

Last updated 1 August 2026

Stocked is an inventory, cost and pricing workspace for Shopify stores. This page explains what it reads from your store, what it deliberately never reads, who else processes it, and how to make it all go away.

Stocked (ABN 13 492 607 793) (“we”, “us”) is a business registered in Australia. For anything on this page, write to privacy@withstocked.com.

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We do this as a matter of policy: as a small business we are not currently bound by that Act, and we have chosen not to rely on that exemption. If your store is in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR also apply to us as your processor, and the rights in section 9 are the wider of the two.

This policy covers the Stocked application, the Stocked Shopify app, and this website. Where you install Stocked on a Shopify store, you are the data controller for your store's data and we act as your processor.

1. What we collect

Your account

When you create a Stocked account we store your name, email address, a hashed password, whether your email is verified, whether two-factor authentication is enabled, an optional profile image, your notification preferences, and the date you signed up. Teammates you invite have accounts of the same shape.

Your store's catalogue and stock

Once you connect a Shopify store, Stocked synchronises and stores:

Your store's sales

Stocked reads your orders to work out how fast each variant sells. What it keeps from an order is deliberately narrow:

Stocked stores no customer personal data — none. No customer names, email addresses, shipping or billing addresses, phone numbers, payment details or customer records of any kind are written to our database at any point. Order data is reduced to units and revenue per variant on arrival.

Shopify treats order data as protected customer data even where it names no customer, so Stocked is approved to read the order lines it needs — the variant, the quantity and the line price. It does not request access to customer names, addresses, phone numbers or email addresses, because it has no use for data it discards.

Competitor pages (only if you use price tracking)

If you use competitor price tracking, Stocked fetches the public product pages of the competitors you nominate and extracts the price. We store the URL, the extracted price and the time it was checked. We do not fetch anything behind a login.

This website

If you join the waiting list, we store the email address you submit and nothing else. The site sets no advertising or analytics cookies.

2. Shopify permissions, and what each one is for

Stocked requests exactly five permissions. Each is used by code that runs — there are no speculative scopes.

PermissionWhy Stocked needs it
write_productsRead your catalogue, and write price and tag changes you approve
write_inventoryRead stock levels, and write quantity and cost changes you approve
read_ordersWork out sales velocity and days of cover, reduced to units and revenue per variant
read_locationsTrack stock per location and address purchase orders correctly
write_filesUpload product images you add from your own computer

3. What we write back to your store

Stocked is not a silo. When you approve a change it is written to Shopify, so your own Shopify reports stay correct. That includes prices, inventory quantities, cost per item, product images, and — only if you switch it on — product tags mirroring your Stocked stock types. Nothing is written to your store without an action from you or a rule you configured and enabled.

4. How we use what we collect

We do not sell personal data, we do not share it for advertising, and we do not use your store's data to train machine-learning models.

5. Who else processes it

ProcessorWhat it handles
RenderApplication hosting and the PostgreSQL database (United States)
ShopifyThe source of your store data, and the billing rail for your subscription
ResendDelivery of transactional email
ScraperAPIFetching the public competitor pages you nominate — used only if you enable price tracking
AnthropicExtracting a price from a fetched competitor page when the direct method fails — used only if you enable price tracking

Competitor page content sent for price extraction is public web-page content from sites you chose. It contains none of your store's data and none of your customers' data.

6. Where it is stored

Stocked's application and database are hosted in the United States. Our sub-processors listed in section 5 may also process data in the United States and the European Union.

We are an Australian company, so your data leaves Australia. We say that plainly because Australian Privacy Principle 8 asks us to name the countries involved, and we take reasonable steps to ensure our overseas providers handle personal information consistently with the Australian Privacy Principles.

If you are in the United Kingdom or the European Economic Area, your data is transferred under the UK International Data Transfer Agreement and the EU Standard Contractual Clauses respectively.

7. How long we keep it

8. Deletion, and Shopify's mandatory requests

Stocked implements the three privacy webhooks Shopify requires of every app:

You can also ask us directly at privacy@withstocked.com and we will action it.

9. Your rights

Everyone. You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Write to privacy@withstocked.com. We will respond within 30 days, and we will not charge you for asking.

Australia. Those are your rights of access and correction under Australian Privacy Principles 12 and 13. If you are unhappy with how we have handled your information, tell us first so we can put it right — and if we do not, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

United Kingdom and the European Economic Area. You additionally have the rights to erasure, to restrict or object to processing, and to receive a portable copy, and you may complain to your own supervisory authority — in the UK, the Information Commissioner's Office.

We have split these deliberately rather than promising everyone the widest version. The Australian Privacy Principles give access and correction; erasure and portability are GDPR rights, and claiming to grant them to everyone would be a nicer sentence than it is a true one. In practice, deleting your store deletes the data either way — see section 8.

10. Security

If a data breach happens that is likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved, and what you should do — we will not wait until we have a complete picture to say something is wrong.

No system is perfectly secure. If you believe you have found a vulnerability in Stocked, please write to help@withstocked.com rather than disclosing it publicly, and we will respond quickly.

11. Cookies

Stocked uses one cookie: the session cookie that keeps you signed in. It is strictly necessary for the application to function, and there is no advertising, tracking or third-party analytics cookie on this website or in the app.

12. Children

Stocked is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.

13. Changes to this policy

If we change this policy we will update the date at the top, and for anything material we will tell you by email or in the app before it takes effect.

14. Contact

Stocked
ABN 13 492 607 793
privacy@withstocked.com

This policy is governed by the law of Victoria, Australia.