Skip to main content
Stockaroo
FeaturesPlatformsPricingLoginStart Free Trial
FeaturesPlatformsPricingLoginStart Free Trial

Privacy Policy

How Stockaroo handles personal data: what we hold, why we are allowed to hold it, who else can see it, and what you can ask us to do with it.

Last updated
10 September 2026
Effective
10 September 2026
Version
1.0
Contents
  1. Who we are
  2. The short version
  3. What we hold
  4. Our two roles
  5. Why we are allowed to hold it
  6. Marketplace connections
  7. Who else sees it
  8. Where it lives and how it is protected
  9. How long we keep it
  10. Your rights
  11. Cookies
  12. Children
  13. Changes to this policy
  14. Contact and complaints

This document is a draft awaiting legal review. It has been written against how Stockaroo actually works, but it has not yet been checked by a solicitor and the highlighted company details still need filling in. Do not rely on it as published policy until both are done.

Who we are

Stockaroo is a multi-channel inventory and order management service for online sellers. It is operated by Harbimoore Ltd, a company registered in Northern Ireland under company number NI739307, with its registered office at 59 Irish Green Street, Limavady, Northern Ireland, BT49 9AA.

In this policy, "we", "us" and "Stockaroo" mean that company. "You" means the person using the service, whether you signed up yourself or someone at your business invited you.

We are the data controller for the account and business information described in this policy. We are registered with the Information Commissioner's Office under registration number [ICO REGISTRATION NUMBER — REQUIRED BEFORE LAUNCH].

The short version

We hold the information needed to run your account, connect your marketplaces, move your stock and orders between them, print your shipping labels, and take your subscription payment. That is the whole of it.

We do not sell your data. We do not share it with advertisers. We do not build profiles of you or your buyers, and we do not use your business data to train machine learning models. The detail below explains exactly what is held and why, but nothing in it contradicts this paragraph.

What we hold

Every category of personal data in the service is listed below, along with why we hold it and when it goes away. If something is not on this list, we do not hold it.

Register of personal data held by Stockaroo. Retention periods run from the date your account closes unless stated otherwise.
WhatWhy we hold itHow long
Name and email addressIdentifying your account, signing you in, sending service email such as verification codes and password resets.30 days
PasswordSigning you in. Stored only as a bcrypt hash, never as text we can read.30 days
Business name, address and phone numberIdentifying your business on invoices, shipping labels and marketplace connections.7 years
Marketplace access tokensReading your listings and orders, and pushing stock levels back. Encrypted at rest with AES-256-GCM.Until you disconnect
Carrier API credentialsBooking shipments and printing labels through Royal Mail Click and Drop and DPD. Encrypted at rest.Until you disconnect
Inventory and listing dataThe core function of the service: keeping stock levels correct across your sales channels.30 days
Buyer name, delivery address, email and phone number on an orderShowing you your orders, grouping them into pick waves, and producing shipping labels. Comes to us from your marketplaces, not from the buyer.30 days after delivery
The order record itself: amounts, tax, currency, dates, items, tracking numberThe transaction record your accountant and HMRC need, and your own sales history.7 years
Billing detailsTaking your subscription payment. Card numbers are handled by Stripe and never reach our servers.7 years
Sign-in and security logsDetecting unauthorised access, investigating incidents, and meeting our security obligations.12 months
Support correspondenceAnswering your questions and keeping a record of what was agreed.2 years

The seven-year periods are set by UK tax and accounting law, which requires records of business transactions to be kept for six full financial years. We cannot shorten those, even at your request. Everything else is deleted on the schedule above.

The two order rows work together rather than contradicting each other. Thirty days after an order is delivered we permanently delete the buyer's name, delivery address, email address, phone number and any note they left, along with the raw copy of the order we received from the marketplace. What remains is the transaction itself — what sold, for how much, when, and which parcel it went in — which is the part tax law requires us to keep and the part that does not identify the buyer. Amazon requires this of everyone connecting to its Selling Partner API; we apply it to Amazon orders today and the same window is available for every other marketplace. The deletion also runs thirty days after you disconnect a sales channel, whatever the age of the orders on it.

Our two roles

Data protection law distinguishes between deciding how data is used and simply handling it on someone else's instructions. Stockaroo does both, depending on whose data it is, and the distinction changes who you should approach.

Your own information: we are the controller

For your name, your sign-in details, your business details and your billing records, we decide what is collected and why. That makes us the controller, and the rights in section 10 are exercised against us directly.

Your buyers' information: we are the processor

When an order arrives from eBay, Amazon, TikTok Shop, Etsy, WooCommerce or Shopify, it carries your buyer's name and delivery address. We hold that data to show you the order and print the label. We do not decide what happens to it; you do. For your buyers' data you are the controller and we are your processor, acting only on your instructions.

This matters in practice: if one of your buyers asks to see or delete their data, the request is yours to answer, not ours. We will help you do it, and we will pass on any request that reaches us by mistake. It also means you need a privacy notice of your own covering your buyers.

Why we are allowed to hold it

UK GDPR requires a lawful basis for each use of personal data. Ours are:

  • Performance of a contract. Your account details, marketplace connections, inventory, orders and billing records. Without these there is no service to provide.
  • Legal obligation. Transaction and invoice records kept for tax and accounting purposes.
  • Legitimate interests. Security logging, fraud prevention, and keeping the service working. We have weighed these against your interests and consider them proportionate, because they are limited to what is needed to keep accounts safe.
  • Consent. Optional analytics cookies, and marketing email if you ask for it. You can withdraw consent at any time without affecting the service.

We do not rely on consent for anything the service needs in order to function, so declining optional cookies will never degrade your account.

Marketplace connections

Connecting a sales channel gives Stockaroo an access token for that marketplace. The token is encrypted with AES-256-GCM before it is stored, and it is only ever decrypted in memory at the moment a request is made.

We use those tokens for exactly three things:

  • Reading your listings, so stock levels can be matched across channels.
  • Reading your orders, so they appear in Stockaroo and can be shipped.
  • Writing stock levels back, so selling an item in one place reduces it everywhere.

We do not use them to place orders, change prices, message buyers, or alter anything else in your marketplace account. Disconnecting a channel deletes its token immediately. The listings and orders already pulled in stay in your account until you delete them or close it.

Who else sees it

We use a small number of subprocessors to run the service. Each one is bound by a data processing agreement and receives only what it needs.

Subprocessors with access to personal data.
WhoWhat they doWhat they receive
StripeSubscription paymentsName, email, billing address, card details entered directly with them
ResendService email deliveryName, email address, message content
Royal MailShipment booking and labelsBuyer name, delivery address, parcel details
DPDShipment booking and labelsBuyer name, delivery address, parcel details
netcup GmbHServers and database hosting, in GermanyAll service data, encrypted at rest

Beyond these, we disclose personal data only where the law requires it, and only to the extent required. If we are ever compelled to hand over your data we will tell you, unless we are legally prohibited from doing so.

We will update this section before adding any new subprocessor, and material additions are announced by email.

Where it lives and how it is protected

Service data is stored on servers in Germany, operated by netcup GmbH. Germany is in the European Economic Area, which the UK government has found to provide an adequate level of data protection, so no additional safeguard is needed for your data to sit there.

Stripe and Resend may process data in the United States. Those transfers rely on UK-approved mechanisms, specifically the International Data Transfer Addendum to the EU Standard Contractual Clauses.

The protections in place:

  • Each customer's business data lives in a separate database, not a shared table with a tenant column. One customer's query cannot reach another's rows.
  • Marketplace and carrier credentials are encrypted at rest with AES-256-GCM.
  • Passwords are stored as bcrypt hashes and cannot be recovered, only reset.
  • Access to production systems is restricted to named staff and logged.
  • Traffic between you and Stockaroo is encrypted with TLS.

No system is perfectly secure, and we would rather say so than imply otherwise. If a breach affects your rights we will tell you and the Information Commissioner's Office within 72 hours of becoming aware of it, as the law requires.

How long we keep it

Retention periods are listed against each category in section 3. In summary: operational data goes 30 days after your account closes, financial records stay for seven years because tax law requires it, and security logs are kept for twelve months.

The 30-day delay is deliberate. It exists so an account closed by mistake, or by a colleague acting too quickly, can be restored. After it passes, deletion is permanent and we cannot recover the data. Backups are purged on a rolling 35-day cycle, so a copy may persist in encrypted backup for a short period after live deletion.

Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything inaccurate. Most of it you can edit yourself in your account settings.
  • Delete your data, subject to records we must keep by law.
  • Restrict or object to how we use it, including anything based on legitimate interests.
  • Export your data in a portable, machine-readable format.
  • Withdraw consent for optional cookies or marketing at any time.

Two of these you can do yourself, without writing to us. The account owner or an admin can download a complete copy of the company's data as a JSON file from the Subscription page, and the account owner can close the account from the same page. Closing it ends billing that day, pauses every marketplace connection, and starts the 30-day retention period described above; after that the company's data is deleted. The account can be reactivated at any point before then.

For anything else, write to privacy@stockaroo.com and we will respond within one month. There is no charge. We may ask you to confirm who you are first, so that nobody else can obtain your data by pretending to be you.

If your request concerns one of your buyers rather than yourself, see section 4: that request belongs to you as controller, and we will support you in answering it.

Cookies

We use the smallest set of cookies the service can run on. Strictly necessary ones keep you signed in, remember your light or dark theme preference, and protect forms from abuse. These cannot be switched off, because the service does not work without them, and UK law does not require consent for them.

Anything beyond that is optional and off until you say otherwise. The banner on your first visit lets you accept or reject optional cookies with equal ease, and you can change your mind at any time from the link in the footer.

At the time of writing we run no analytics or advertising cookies at all. If that changes, the banner will ask before anything is set, and this section will be updated first.

Children

Stockaroo is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

Changes to this policy

When this policy changes, the version number and date at the top change with it. Minor corrections are made quietly. Anything that materially affects how your data is used will be emailed to you at least 30 days before it takes effect, so you have time to object or close your account.

We keep previous versions and will send you any of them on request.

Contact and complaints

Privacy questions and rights requests:privacy@stockaroo.com

Everything else:support@stockaroo.com

Post: Harbimoore Ltd, 59 Irish Green Street, Limavady, Northern Ireland, BT49 9AA

Complaining to us

You have the right to complain to us directly about how we have handled your personal data, and we have a duty to deal with it properly. This is what we commit to:

How to complain
Any channel you like — email privacy@stockaroo.com, write to the address above, or simply say so in a support message. You do not have to use a particular form of words or call it a complaint.
Acknowledgement
We will confirm we have received it within 30 days, and tell you who is looking at it.
Outcome
We will investigate and tell you what we found and what we have done. If it is going to take longer than we expected, we will say so rather than go quiet.
Records
We keep a record of every complaint, when it arrived, what we did and how it ended — including the ones we did not uphold.

Complaining to us is not a prerequisite for anything and does not limit your rights.

Complaining to the regulator

You can complain to the Information Commissioner's Office, the UK's data protection regulator, at ico.org.uk, or on 0303 123 1113. You do not need our permission, you do not have to come to us first, and complaining to them does not affect your rights against us.

Stockaroo

One stash, every store. Multi-channel inventory and sales, finally in one place.

Product

  • Features
  • Pricing
  • Integrations

Company

  • Contact
  • Report a vulnerability

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Stockaroo. All rights reserved.