Privacy Policy
Stockisto is the record of the channel for product suppliers and their networks. This policy explains what personal data we process and why. It names our lawful bases, who we share data with, and how long we keep each type. It also explains your rights under the EU General Data Protection Regulation (GDPR). We wrote it to describe what the product actually does, not to fill a template.
1. Who we are, and our two roles
Stockisto is operated by Goty Invest AB (org. no. 559006-5651). The Stockisto platform includes the consumer Locator, the embeddable Widget, the Supplier and Retailer Admin apps, the Installer Portal, and this marketing site.
We act in two distinct roles:
- Controller, meaning we decide why and how data is processed. We are the controller for our own account users, our business contacts, and visitors to this marketing site. This policy governs that processing.
- Processor, meaning we handle data only on someone else's instructions. Our supplier and retailer customers upload or generate personal data through the platform, such as their retailer contacts and consumers who make a reservation. For that data, the customer is the controller. We must process it only on the customer's documented instructions under our Data Processing Agreement.
2. What we collect, and from whom
- Account & identity data: name, work email, phone number, company, and role. You provide these when a workspace is created or a user is invited. If you sign in with Google, we take them from your Google profile.
- Authentication data: session cookies, single-use magic-link tokens, and OAuth identifiers. We use them only to sign you in and keep you signed in.
- Retailer network data: the retailer business contacts (name, address, phone, email) a supplier uploads or imports. These may occasionally include the personal data of a sole trader.
- Consumer reservation data: the name, email, phone, and any notes a shopper enters in a supplier's public “reserve & collect” form. No account is needed and none is created.
- Discovery & usage analytics: anonymised events that describe how the Locator and admin apps are used. They carry no consumer identity. We do not store IP addresses in the analytics record.
- Marketing-site data: a newsletter email if you subscribe, and campaign or referral labels from the link you arrived on (see the Cookie Policy).
- Technical & log data: correlation identifiers and opaque IDs. Our logging policy must keep direct identifiers, such as email addresses, out of application logs.
3. Our lawful bases (Art 6 GDPR)
- Performance of a contract (Art 6(1)(b)): we process account data to provide the platform to the users of a workspace.
- Legitimate interests (Art 6(1)(f)), meaning purposes of ours that may not override your rights: we operate, secure, and improve the platform, produce B2B discovery analytics, and contact business contacts about the service. We must balance these interests against yours. You may object (section 7).
- Consent (Art 6(1)(a)): we set the non-essential analytics and attribution cookies on this marketing site, and send the newsletter, only if you agree. You may withdraw consent at any time.
- Legal obligation (Art 6(1)(c)): we must keep billing and accounting records, and we must honour data-subject rights requests.
- For personal data we process on a customer's behalf, that customer chooses the lawful basis as controller. We must act only on the customer's instructions.
5. International transfers (Chapter V)
6. How long we keep it
| Data | Retention | Basis |
|---|---|---|
| Account & user profile data (name, work email, phone, role) | For the lifetime of the workspace; deleted on account closure via the export/erasure process below | Contract; legitimate interest |
| Consumer reservation details (name, email, phone, notes) | Automatically erased 30 days after the reservation expires | Data minimisation (Art 5(1)(e)) |
| Discovery & usage analytics (no consumer identity; IP not stored) | Rolling operational window; only aggregated, non-identifying metrics are retained beyond it | Legitimate interest |
| Administrative audit log (privileged tenant actions) | 7 years | Legal obligation / accountability (Art 5(2)) |
| Application performance & error telemetry | 90 days (non-production) / 365 days (production); client IP truncated and not persisted in analytics | Legitimate interest (security & reliability) |
| Backups (point-in-time) | Up to 35 days, geo-redundant within the EU | Resilience / disaster recovery |
| Marketing-site cookies (consent, campaign & referral labels) | See the Cookie Policy: consent 12 months; campaign/referral labels 30 days | Consent |
| Billing & invoicing records | As required by applicable accounting & tax law | Legal obligation (Art 6(1)(c)) |
7. Your rights
Under the GDPR you have the right to:
- access your data (Art 15)
- have it corrected (Art 16, “rectification”)
- have it erased (Art 17)
- restrict how it is used (Art 18)
- receive it in a portable format (Art 20, “data portability”)
- object to processing based on our legitimate interests (Art 21)
Where processing rests on your consent, you may withdraw it at any time. Withdrawal does not affect processing that already happened.
How to exercise them.
- You are a workspace admin: you may run a full data export (Art 20) and request deletion (Art 17) directly in the product. Deletion starts a 14-day grace period, and you may cancel it during that time.
- You need anything else: email privacy@stockisto.com. We must reply within one month (Art 12(3)).
- You gave your data to a supplier or retailer (for example, in a reservation): that customer is the controller, so contact them. We must assist them as their processor.
You may also lodge a complaint with a supervisory authority. In Sweden, that is the Swedish Authority for Privacy Protection (IMY). Elsewhere, contact your local EU/EEA data-protection authority.
8. Businesses we list from public sources (Art 14)
Our directory of Nordic retailers, brands and installers is built partly from what businesses already publish about themselves. If your details are in it and you never gave them to us, this section is the notice the GDPR requires when data is not collected from you (Art 14).
- What we hold. Business identity data: company name, address, phone, email, website, opening hours and org number. Where a business publishes a named contact person instead of a general address, we also hold that person's name, work email, work phone and role.
- Where it came from. Pages that are open to anyone: supplier “where to buy” pages, company websites, and public business registers. We never collect from behind a login, a paywall or any other access control.
- Why. To run a directory that helps consumers find where to buy, to let each business claim and correct its own entry, and to keep the records accurate.
- Lawful basis. Legitimate interests (Art 6(1)(f)). We ran a balancing test before we started. Ask privacy@stockisto.com for a summary of it.
- Who sees it. The business details are public: that is the directory. A named contact person's details are internal only. We never show them to consumers. Our sub-processors are listed in section 4.
- How long we keep it. Entity records last while the business is in the market and its listing is live. Our retention target for a named contact at a business that never claims its entry is 24 months from when we last saw it published. Be aware that no automated purge enforces that target yet, so today we cannot promise it as a limit. Until it is enforced, ask privacy@stockisto.com and we will delete a contact on request.
- No automated decisions. We make no decision about you by automated means, and we do not profile you.
Your rights, and how to use them. You have every right in section 7. Two are the quick routes here:
- Object (Art 21). You can object to this processing at any time. Write to privacy@stockisto.com. We stop unless we can show compelling grounds that override your objection. For outreach email there are none, so we stop.
- Take a listing down. Use our removal form. You need no account, a person reviews every request, and an approved removal also blocks the listing from coming back on the next import.
- Own the business? Claiming your listing is free and is the fastest way to correct it.
Our crawler identifies itself as StockistoMarketDataBot. Site operators can read what it does, and how to block it, on our crawler page. That address, crawler@stockisto.com, is for technical crawl questions. Send privacy requests to privacy@stockisto.com so they reach the right people.
9. Consumers using a locator
11. Security
We protect personal data with:
- encryption in transit and at rest
- tenant isolation at the data layer
- role-based access control
- audit logging
- a managed secrets store
The full technical and organisational measures are in Annex 2 of our Data Processing Agreement and on our security page.