GDPR

What StockFlow actually does with personal and warehouse data—controls that ship today, and gaps we do not hide.

By Tibeau De Grauwe, FounderUpdated August 2026

  • 25 products free
  • No credit card
  • 10-min setup
Findings from the live product—not brochure compliance

GDPR as implemented in StockFlow

This page mirrors controls and data flows that exist in the app, edge functions, and published policies. If a common checklist item is missing, it is listed under What we do not claim.

Roles under GDPR

Short version of who decides purpose and means for which data.

You as account holder

Controller of the inventory, supplier, and customer records you enter. StockFlow processes that data on your instructions to provide the service.

StockFlow

Controller of account identity data (name, email, auth), billing metadata, support communications, and product analytics needed to operate and improve the service. Processor for your warehouse content.

Available today

Controls and practices you can verify in the product or by contacting us.

EU company / GDPR scope

StockFlow Systems is based in Belgium. GDPR applies to how we handle personal data of EU/EEA users and to processing we perform as your processor.

Encryption in transit and at rest

TLS for traffic. Cloud database encryption at rest on Supabase. Details and gaps (no SSO/MFA yet) are on Security & Trust.

Warehouse roles and export gating

Owner, admin, and staff presets with granular permissions. data.export controls who can download inventory and reporting data; data.delete_all is owner-only.

Self-serve data export

CSV export for products, inventory levels, stock transactions, and assets (permission-gated). Paid plans unlock broader reporting/export; Starter still lets you leave with your catalog via import/export workflows.

Self-serve account deletion

Settings → Profile → Delete account calls our delete-user service: cancels Stripe subscriptions, clears invitations and memberships, deletes user-scoped tables, then removes the auth user.

Movement and activity history

Stock movements and asset check-in/check-out include who acted and when. Branch activity log supports day-to-day accountability inside your team.

Your inventory stays yours

We do not sell warehouse content for ads. Subprocessors (hosting, auth/db, payments, email) process data only to run the product. Subprocessor list on request via info@stockflowsystems.com.

Email you can control

Operational mail (invites, stock alerts, weekly digest). Weekly digest can be turned off per warehouse under Settings. Rights requests: info@stockflowsystems.com / info@stockflowsystems.com.

Personal data categories we process

Drawn from account creation, warehouse usage, billing, and product analytics—not a generic template list.

  • Account & auth

    Name, email, password hash (or Google OAuth identity), profile fields, invite tokens.

  • Business content you enter

    Products, SKUs, stock levels, movements, suppliers, customers, POs/SOs, assets, BOM/production records.

  • Team & access

    Warehouse memberships, role presets, granular permission keys, invitation history.

  • Billing

    Plan and subscription status; card data handled by Stripe (we do not store full card numbers).

  • Product analytics

    App events (route, session, device type, locale) stored in our database to improve the product. Owner/admin tooling traffic is excluded from product analytics aggregates.

  • Marketing site signals

    Essential cookies for the app session. No separate cookie preference UI yet.

How to exercise your rights

Prefer self-serve paths when they exist; email for everything else.

  • Access / portability

    Export CSV from the app where you have data.export, or email info@stockflowsystems.com for a broader copy of personal data we hold.

  • Rectification

    Edit profile under Settings → Profile; edit warehouse records in-app. Contact support if something is stuck.

  • Erasure

    Delete account under Settings → Profile, or request erasure at info@stockflowsystems.com / info@stockflowsystems.com. Legal retention (e.g. billing fraud prevention) may apply to limited records.

  • Restrict / object

    Email info@stockflowsystems.com. Turn off weekly digest in warehouse settings. Auth is required to use the product; we cannot run an anonymous full inventory account.

After account closure, we aim to delete or anonymize personal data within 90 days except where law requires longer retention (see Privacy Policy).

What we do not claim

Procurement and privacy reviewers should treat these as open items, not marketing omissions.

  • Formal ISO 27001 / SOC 2 Type II attestation for the StockFlow product (host certifications ≠ our attestation)
  • In-app Data Processing Agreement (DPA) download request a DPA via info@stockflowsystems.com
  • Cookie consent banner / granular marketing-cookie preferences on the marketing site
  • Customer-chosen data residency regions, on-prem, or air-gapped deploy
  • SAML/OIDC SSO or enforced MFA (on the security roadmap)
  • Customer-facing SIEM export or compliance audit console

Contact

Privacy: info@stockflowsystems.com

Data Protection Officer: info@stockflowsystems.com

Security reports: info@stockflowsystems.com

Address: StockFlow Systems, Belgium

Trusted by small businesses

What our customers say

Super Kind! Quick replies from their support and very easy fixes, changed the dashboard a bit and customized it. Also gave me 450 items extra on the free plan just for me. Highly recommend and again great service!

Erasable Trading AU

Best customer service! Stockflow's customer support is fast and extremely helpful. They assisted me with customization of the software to improve my experience as a user.

Justin M.

Co-Owner, Consumer Goods

Frequently asked questions

Is StockFlow GDPR compliant as a controller or a processor?
StockFlow is a Belgium-based company and processes personal data under the GDPR as a controller for account data and as a processor for the inventory and contact data you enter. Encryption in transit and at rest, warehouse role permissions, self-serve account deletion, and CSV export are available today. We do not claim a formal certification stamp beyond operating under GDPR; see this page and our Privacy Policy for what ships versus what is still missing (e.g. cookie banner, SSO/MFA).
Where is my data stored?
Application data is stored with our cloud database provider (Supabase) with TLS in transit and encryption at rest. StockFlow is based in Belgium. Customer-chosen region selection, on-premises deployment, and air-gapped hosting are not available today.
How do I export or delete my data?
Managers with the data.export permission can download inventory and reporting data from the app (CSV export for products, inventory, transactions, and assets). To delete your account and associated personal data, go to Settings → Profile and use Delete account. That flow cancels active Stripe subscriptions, removes warehouse memberships and invitations, deletes user-owned records, and removes the auth user. For rights requests beyond self-serve tools, email info@stockflowsystems.com or info@stockflowsystems.com.
Do you sell inventory or personal data?
No. Product names, SKUs, quantities, suppliers, and customers you enter remain your business data. We process them to run the product. We do not sell, mine, or use your inventory data for advertising.