Privacy Policy
How Stockaroo handles personal data: what we hold, why we are allowed to hold it, who else can see it, and what you can ask us to do with it.
- Last updated
- 10 September 2026
- Effective
- 10 September 2026
- Version
- 1.0
Contents
This document is a draft awaiting legal review. It has been written against how Stockaroo actually works, but it has not yet been checked by a solicitor and the highlighted company details still need filling in. Do not rely on it as published policy until both are done.
Who we are
Stockaroo is a multi-channel inventory and order management service for online sellers. It is operated by Harbimoore Ltd, a company registered in Northern Ireland under company number NI739307, with its registered office at 59 Irish Green Street, Limavady, Northern Ireland, BT49 9AA.
In this policy, "we", "us" and "Stockaroo" mean that company. "You" means the person using the service, whether you signed up yourself or someone at your business invited you.
We are the data controller for the account and business information described in this policy. We are registered with the Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER — REQUIRED BEFORE LAUNCH].
The short version
We hold the information needed to run your account, connect your marketplaces, move your stock and orders between them, print your shipping labels, and take your subscription payment. That is the whole of it.
We do not sell your data. We do not share it with advertisers. We do not build profiles of you or your buyers, and we do not use your business data to train machine learning models. The detail below explains exactly what is held and why, but nothing in it contradicts this paragraph.
What we hold
Every category of personal data in the service is listed below, along with why we hold it and when it goes away. If something is not on this list, we do not hold it.
| What | Why we hold it | How long |
|---|---|---|
| Name and email address | Identifying your account, signing you in, sending service email such as verification codes and password resets. | 30 days |
| Password | Signing you in. Stored only as a bcrypt hash, never as text we can read. | 30 days |
| Business name, address and phone number | Identifying your business on invoices, shipping labels and marketplace connections. | 7 years |
| Marketplace access tokens | Reading your listings and orders, and pushing stock levels back. Encrypted at rest with AES-256-GCM. | Until you disconnect |
| Carrier API credentials | Booking shipments and printing labels through Royal Mail Click and Drop and DPD. Encrypted at rest. | Until you disconnect |
| Inventory and listing data | The core function of the service: keeping stock levels correct across your sales channels. | 30 days |
| Buyer name, delivery address, email and phone number on an order | Showing you your orders, grouping them into pick waves, and producing shipping labels. Comes to us from your marketplaces, not from the buyer. | 30 days after delivery |
| The order record itself: amounts, tax, currency, dates, items, tracking number | The transaction record your accountant and HMRC need, and your own sales history. | 7 years |
| Billing details | Taking your subscription payment. Card numbers are handled by Stripe and never reach our servers. | 7 years |
| Sign-in and security logs | Detecting unauthorised access, investigating incidents, and meeting our security obligations. | 12 months |
| Support correspondence | Answering your questions and keeping a record of what was agreed. | 2 years |
The seven-year periods are set by UK tax and accounting law, which requires records of business transactions to be kept for six full financial years. We cannot shorten those, even at your request. Everything else is deleted on the schedule above.
The two order rows work together rather than contradicting each other. Thirty days after an order is delivered we permanently delete the buyer's name, delivery address, email address, phone number and any note they left, along with the raw copy of the order we received from the marketplace. What remains is the transaction itself — what sold, for how much, when, and which parcel it went in — which is the part tax law requires us to keep and the part that does not identify the buyer. Amazon requires this of everyone connecting to its Selling Partner API; we apply it to Amazon orders today and the same window is available for every other marketplace. The deletion also runs thirty days after you disconnect a sales channel, whatever the age of the orders on it.
Our two roles
Data protection law distinguishes between deciding how data is used and simply handling it on someone else's instructions. Stockaroo does both, depending on whose data it is, and the distinction changes who you should approach.
Your own information: we are the controller
For your name, your sign-in details, your business details and your billing records, we decide what is collected and why. That makes us the controller, and the rights in section 10 are exercised against us directly.
Your buyers' information: we are the processor
When an order arrives from eBay, Amazon, TikTok Shop, Etsy, WooCommerce or Shopify, it carries your buyer's name and delivery address. We hold that data to show you the order and print the label. We do not decide what happens to it; you do. For your buyers' data you are the controller and we are your processor, acting only on your instructions.
This matters in practice: if one of your buyers asks to see or delete their data, the request is yours to answer, not ours. We will help you do it, and we will pass on any request that reaches us by mistake. It also means you need a privacy notice of your own covering your buyers.
Why we are allowed to hold it
UK GDPR requires a lawful basis for each use of personal data. Ours are:
- Performance of a contract. Your account details, marketplace connections, inventory, orders and billing records. Without these there is no service to provide.
- Legal obligation. Transaction and invoice records kept for tax and accounting purposes.
- Legitimate interests. Security logging, fraud prevention, and keeping the service working. We have weighed these against your interests and consider them proportionate, because they are limited to what is needed to keep accounts safe.
- Consent. Optional analytics cookies, and marketing email if you ask for it. You can withdraw consent at any time without affecting the service.
We do not rely on consent for anything the service needs in order to function, so declining optional cookies will never degrade your account.
Marketplace connections
Connecting a sales channel gives Stockaroo an access token for that marketplace. The token is encrypted with AES-256-GCM before it is stored, and it is only ever decrypted in memory at the moment a request is made.
We use those tokens for exactly three things:
- Reading your listings, so stock levels can be matched across channels.
- Reading your orders, so they appear in Stockaroo and can be shipped.
- Writing stock levels back, so selling an item in one place reduces it everywhere.
We do not use them to place orders, change prices, message buyers, or alter anything else in your marketplace account. Disconnecting a channel deletes its token immediately. The listings and orders already pulled in stay in your account until you delete them or close it.
Who else sees it
We use a small number of subprocessors to run the service. Each one is bound by a data processing agreement and receives only what it needs.
| Who | What they do | What they receive |
|---|---|---|
| Stripe | Subscription payments | Name, email, billing address, card details entered directly with them |
| Resend | Service email delivery | Name, email address, message content |
| Royal Mail | Shipment booking and labels | Buyer name, delivery address, parcel details |
| DPD | Shipment booking and labels | Buyer name, delivery address, parcel details |
| netcup GmbH | Servers and database hosting, in Germany | All service data, encrypted at rest |
Beyond these, we disclose personal data only where the law requires it, and only to the extent required. If we are ever compelled to hand over your data we will tell you, unless we are legally prohibited from doing so.
We will update this section before adding any new subprocessor, and material additions are announced by email.
Where it lives and how it is protected
Service data is stored on servers in Germany, operated by netcup GmbH. Germany is in the European Economic Area, which the UK government has found to provide an adequate level of data protection, so no additional safeguard is needed for your data to sit there.
Stripe and Resend may process data in the United States. Those transfers rely on UK-approved mechanisms, specifically the International Data Transfer Addendum to the EU Standard Contractual Clauses.
The protections in place:
- Each customer's business data lives in a separate database, not a shared table with a tenant column. One customer's query cannot reach another's rows.
- Marketplace and carrier credentials are encrypted at rest with AES-256-GCM.
- Passwords are stored as bcrypt hashes and cannot be recovered, only reset.
- Access to production systems is restricted to named staff and logged.
- Traffic between you and Stockaroo is encrypted with TLS.
No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects your rights we will tell you and the Information Commissioner's Office within 72 hours of becoming aware of it, as the law requires.
How long we keep it
Retention periods are listed against each category in section 3. In summary: operational data goes 30 days after your account closes, financial records stay for seven years because tax law requires it, and security logs are kept for twelve months.
The 30-day delay is deliberate. It exists so an account closed by mistake, or by a colleague acting too quickly, can be restored. After it passes, deletion is permanent and we cannot recover the data. Backups are purged on a rolling 35-day cycle, so a copy may persist in encrypted backup for a short period after live deletion.
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate. Most of it you can edit yourself in your account settings.
- Delete your data, subject to records we must keep by law.
- Restrict or object to how we use it, including anything based on legitimate interests.
- Export your data in a portable, machine-readable format.
- Withdraw consent for optional cookies or marketing at any time.
Two of these you can do yourself, without writing to us. The account owner or an admin can download a complete copy of the company's data as a JSON file from the Subscription page, and the account owner can close the account from the same page. Closing it ends billing that day, pauses every marketplace connection, and starts the 30-day retention period described above; after that the company's data is deleted. The account can be reactivated at any point before then.
For anything else, write to privacy@stockaroo.com and we will respond within one month. There is no charge. We may ask you to confirm who you are first, so that nobody else can obtain your data by pretending to be you.
If your request concerns one of your buyers rather than yourself, see section 4: that request belongs to you as controller, and we will support you in answering it.
Children
Stockaroo is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
When this policy changes, the version number and date at the top change with it. Minor corrections are made quietly. Anything that materially affects how your data is used will be emailed to you at least 30 days before it takes effect, so you have time to object or close your account.
We keep previous versions and will send you any of them on request.
Contact and complaints
Privacy questions and rights requests:privacy@stockaroo.com
Everything else:support@stockaroo.com
Post: Harbimoore Ltd, 59 Irish Green Street, Limavady, Northern Ireland, BT49 9AA
Complaining to us
You have the right to complain to us directly about how we have handled your personal data, and we have a duty to deal with it properly. This is what we commit to:
- How to complain
- Any channel you like — email privacy@stockaroo.com, write to the address above, or simply say so in a support message. You do not have to use a particular form of words or call it a complaint.
- Acknowledgement
- We will confirm we have received it within 30 days, and tell you who is looking at it.
- Outcome
- We will investigate and tell you what we found and what we have done. If it is going to take longer than we expected, we will say so rather than go quiet.
- Records
- We keep a record of every complaint, when it arrived, what we did and how it ended — including the ones we did not uphold.
Complaining to us is not a prerequisite for anything and does not limit your rights.
Complaining to the regulator
You can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk, or on 0303 123 1113. You do not need our permission, you do not have to come to us first, and complaining to them does not affect your rights against us.