Privacy Policy
Last updated 1 August 2026
Stocked is an inventory, cost and pricing workspace for Shopify stores. This page explains what it reads from your store, what it deliberately never reads, who else processes it, and how to make it all go away.
Stocked (ABN 13 492 607 793) (“we”, “us”) is a business registered in Australia. For anything on this page, write to privacy@withstocked.com.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We do this as a matter of policy: as a small business we are not currently bound by that Act, and we have chosen not to rely on that exemption. If your store is in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR also apply to us as your processor, and the rights in section 9 are the wider of the two.
This policy covers the Stocked application, the Stocked Shopify app, and this website. Where you install Stocked on a Shopify store, you are the data controller for your store's data and we act as your processor.
1. What we collect
Your account
When you create a Stocked account we store your name, email address, a hashed password, whether your email is verified, whether two-factor authentication is enabled, an optional profile image, your notification preferences, and the date you signed up. Teammates you invite have accounts of the same shape.
Your store's catalogue and stock
Once you connect a Shopify store, Stocked synchronises and stores:
- Products, variants, product options, product media and tags
- Inventory locations, including the business address and phone number you have set on each location in Shopify — used so a purchase order can tell a supplier where to deliver
- Inventory levels per variant per location (available, committed, incoming, on hand)
- Costs and prices, including the landed costs Stocked calculates
- Suppliers, purchase orders and receiving records that you create in Stocked
Your store's sales
Stocked reads your orders to work out how fast each variant sells. What it keeps from an order is deliberately narrow:
- The order's Shopify identifier and the date it was created
- Per variant: the number of units and the revenue
Stocked stores no customer personal data — none. No customer names, email addresses, shipping or billing addresses, phone numbers, payment details or customer records of any kind are written to our database at any point. Order data is reduced to units and revenue per variant on arrival.
Shopify treats order data as protected customer data even where it names no customer, so Stocked is approved to read the order lines it needs — the variant, the quantity and the line price. It does not request access to customer names, addresses, phone numbers or email addresses, because it has no use for data it discards.
Competitor pages (only if you use price tracking)
If you use competitor price tracking, Stocked fetches the public product pages of the competitors you nominate and extracts the price. We store the URL, the extracted price and the time it was checked. We do not fetch anything behind a login.
This website
If you join the waiting list, we store the email address you submit and nothing else. The site sets no advertising or analytics cookies.
2. Shopify permissions, and what each one is for
Stocked requests exactly five permissions. Each is used by code that runs — there are no speculative scopes.
| Permission | Why Stocked needs it |
|---|---|
write_products | Read your catalogue, and write price and tag changes you approve |
write_inventory | Read stock levels, and write quantity and cost changes you approve |
read_orders | Work out sales velocity and days of cover, reduced to units and revenue per variant |
read_locations | Track stock per location and address purchase orders correctly |
write_files | Upload product images you add from your own computer |
3. What we write back to your store
Stocked is not a silo. When you approve a change it is written to Shopify, so your own Shopify reports stay correct. That includes prices, inventory quantities, cost per item, product images, and — only if you switch it on — product tags mirroring your Stocked stock types. Nothing is written to your store without an action from you or a rule you configured and enabled.
4. How we use what we collect
- To run the product: stock levels, landed cost, forecasting, purchase orders, alerts, reports
- To keep an audit trail — who changed what, when, and from what to what
- To send transactional email: password resets, stock alerts you configured, and mentions from teammates
- To bill you through Shopify, and to support you when you ask
- To keep the service secure and diagnose faults
We do not sell personal data, we do not share it for advertising, and we do not use your store's data to train machine-learning models.
5. Who else processes it
| Processor | What it handles |
|---|---|
| Render | Application hosting and the PostgreSQL database (United States) |
| Shopify | The source of your store data, and the billing rail for your subscription |
| Resend | Delivery of transactional email |
| ScraperAPI | Fetching the public competitor pages you nominate — used only if you enable price tracking |
| Anthropic | Extracting a price from a fetched competitor page when the direct method fails — used only if you enable price tracking |
Competitor page content sent for price extraction is public web-page content from sites you chose. It contains none of your store's data and none of your customers' data.
6. Where it is stored
Stocked's application and database are hosted in the United States. Our sub-processors listed in section 5 may also process data in the United States and the European Union.
We are an Australian company, so your data leaves Australia. We say that plainly because Australian Privacy Principle 8 asks us to name the countries involved, and we take reasonable steps to ensure our overseas providers handle personal information consistently with the Australian Privacy Principles.
If you are in the United Kingdom or the European Economic Area, your data is transferred under the UK International Data Transfer Agreement and the EU Standard Contractual Clauses respectively.
7. How long we keep it
- Store data — for as long as the store is connected. Uninstalling the app from Shopify, or asking us to delete it, removes it.
- Account data — until you delete your account.
- Audit records — kept for the life of the store, because their whole purpose is to answer “who changed this, and when”.
- Waiting-list emails — until you ask us to remove yours.
8. Deletion, and Shopify's mandatory requests
Stocked implements the three privacy webhooks Shopify requires of every app:
customers/data_request— we record the request and confirm that we hold no customer personal data to return.customers/redact— we record the request and confirm there is no customer personal data to erase.shop/redact— we permanently delete the store and every record belonging to it. This is a hard delete, not a flag.
You can also ask us directly at privacy@withstocked.com and we will action it.
9. Your rights
Everyone. You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Write to privacy@withstocked.com. We will respond within 30 days, and we will not charge you for asking.
Australia. Those are your rights of access and correction under Australian Privacy Principles 12 and 13. If you are unhappy with how we have handled your information, tell us first so we can put it right — and if we do not, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
United Kingdom and the European Economic Area. You additionally have the rights to erasure, to restrict or object to processing, and to receive a portable copy, and you may complain to your own supervisory authority — in the UK, the Information Commissioner's Office.
We have split these deliberately rather than promising everyone the widest version. The Australian Privacy Principles give access and correction; erasure and portability are GDPR rights, and claiming to grant them to everyone would be a nicer sentence than it is a true one. In practice, deleting your store deletes the data either way — see section 8.
10. Security
- Your Shopify access token is encrypted at rest with AES-256-GCM. It is never displayed in the product and never written to logs.
- Access tokens are short-lived and refreshed automatically.
- Passwords are stored hashed, never in plain text.
- All traffic is served over HTTPS, and session cookies are restricted to secure connections.
- Access inside Stocked is governed by roles and permissions you assign to your teammates, and every change is recorded in the audit trail.
If a data breach happens that is likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved, and what you should do — we will not wait until we have a complete picture to say something is wrong.
No system is perfectly secure. If you believe you have found a vulnerability in Stocked, please write to help@withstocked.com rather than disclosing it publicly, and we will respond quickly.
11. Cookies
Stocked uses one cookie: the session cookie that keeps you signed in. It is strictly necessary for the application to function, and there is no advertising, tracking or third-party analytics cookie on this website or in the app.
12. Children
Stocked is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
If we change this policy we will update the date at the top, and for anything material we will tell you by email or in the app before it takes effect.
14. Contact
Stocked
ABN 13 492 607 793
privacy@withstocked.com
This policy is governed by the law of Victoria, Australia.