Privacy Policy

Last updated: 12 August 2026

1. Who we are

Stoket is an inventory, ordering and forecasting platform for cafés, restaurants and franchise groups. This policy explains what data we process and why. For GDPR purposes, the organisation using Stoket is the controller of its business data; we act as processor on its behalf.

2. Data we process

  • Account data: email address, display name, role and store assignment.
  • Business data: products, vendors, orders, inventory movements, recipes, revenue.
  • Uploaded images of products, stored privately and served via signed links.
  • Technical data: log and error information needed to operate the Service.

We do not intentionally collect special categories of personal data.

3. Why we process it

To provide the Service (contract), to keep it secure and prevent abuse (legitimate interest), and to comply with legal obligations. Where required, we rely on consent, which you may withdraw at any time.

4. Data separation and access

Each organisation’s data is isolated at the database level using row-level security. Access within an organisation is further restricted by role: cost and financial figures are visible only to owners, totals only to franchise owners, and store staff see product names, units and quantities.

5. Processors

We use a managed cloud database and authentication provider for storage and login, and an AI model provider for forecasting and vendor price comparison features. Data sent to AI providers is limited to what is needed for the requested analysis and is not used to train public models by us.

6. Retention

Business data is retained while your account is active. After termination you may request an export or deletion; residual copies in backups are removed on the normal backup cycle.

7. Your rights

Subject to applicable law (including the GDPR), you may request access, correction, deletion, restriction, portability, or object to processing. Contact your organisation administrator, who can escalate the request to us.

8. Security

We use encrypted transport, private storage buckets with signed URLs, role-based access control and row-level security. No system is perfectly secure; please report suspected issues promptly.

9. Changes

We may update this policy as the Service evolves. Material changes will be reflected in the “last updated” date above.