GDPR as implemented in StockFlow
This page mirrors controls and data flows that exist in the app, edge functions, and published policies. If a common checklist item is missing, it is listed under What we do not claim.
Roles under GDPR
Short version of who decides purpose and means for which data.
You as account holder
Controller of the inventory, supplier, and customer records you enter. StockFlow processes that data on your instructions to provide the service.
StockFlow
Controller of account identity data (name, email, auth), billing metadata, support communications, and product analytics needed to operate and improve the service. Processor for your warehouse content.
Available today
Controls and practices you can verify in the product or by contacting us.
EU company / GDPR scope
StockFlow Systems is based in Belgium. GDPR applies to how we handle personal data of EU/EEA users and to processing we perform as your processor.
Encryption in transit and at rest
TLS for traffic. Cloud database encryption at rest on Supabase. Details and gaps (no SSO/MFA yet) are on Security & Trust.
Warehouse roles and export gating
Owner, admin, and staff presets with granular permissions. data.export controls who can download inventory and reporting data; data.delete_all is owner-only.
Self-serve data export
CSV export for products, inventory levels, stock transactions, and assets (permission-gated). Paid plans unlock broader reporting/export; Starter still lets you leave with your catalog via import/export workflows.
Self-serve account deletion
Settings → Profile → Delete account calls our delete-user service: cancels Stripe subscriptions, clears invitations and memberships, deletes user-scoped tables, then removes the auth user.
Movement and activity history
Stock movements and asset check-in/check-out include who acted and when. Branch activity log supports day-to-day accountability inside your team.
Your inventory stays yours
We do not sell warehouse content for ads. Subprocessors (hosting, auth/db, payments, email) process data only to run the product. Subprocessor list on request via info@stockflowsystems.com.
Email you can control
Operational mail (invites, stock alerts, weekly digest). Weekly digest can be turned off per warehouse under Settings. Rights requests: info@stockflowsystems.com / info@stockflowsystems.com.
Personal data categories we process
Drawn from account creation, warehouse usage, billing, and product analytics—not a generic template list.
Account & auth
Name, email, password hash (or Google OAuth identity), profile fields, invite tokens.
Business content you enter
Products, SKUs, stock levels, movements, suppliers, customers, POs/SOs, assets, BOM/production records.
Team & access
Warehouse memberships, role presets, granular permission keys, invitation history.
Billing
Plan and subscription status; card data handled by Stripe (we do not store full card numbers).
Product analytics
App events (route, session, device type, locale) stored in our database to improve the product. Owner/admin tooling traffic is excluded from product analytics aggregates.
Marketing site signals
Essential cookies for the app session. No separate cookie preference UI yet.
How to exercise your rights
Prefer self-serve paths when they exist; email for everything else.
Access / portability
Export CSV from the app where you have data.export, or email info@stockflowsystems.com for a broader copy of personal data we hold.
Rectification
Edit profile under Settings → Profile; edit warehouse records in-app. Contact support if something is stuck.
Erasure
Delete account under Settings → Profile, or request erasure at info@stockflowsystems.com / info@stockflowsystems.com. Legal retention (e.g. billing fraud prevention) may apply to limited records.
Restrict / object
Email info@stockflowsystems.com. Turn off weekly digest in warehouse settings. Auth is required to use the product; we cannot run an anonymous full inventory account.
After account closure, we aim to delete or anonymize personal data within 90 days except where law requires longer retention (see Privacy Policy).
What we do not claim
Procurement and privacy reviewers should treat these as open items, not marketing omissions.
- Formal ISO 27001 / SOC 2 Type II attestation for the StockFlow product (host certifications ≠ our attestation)
- In-app Data Processing Agreement (DPA) download request a DPA via info@stockflowsystems.com
- Cookie consent banner / granular marketing-cookie preferences on the marketing site
- Customer-chosen data residency regions, on-prem, or air-gapped deploy
- SAML/OIDC SSO or enforced MFA (on the security roadmap)
- Customer-facing SIEM export or compliance audit console
Contact
Privacy: info@stockflowsystems.com
Data Protection Officer: info@stockflowsystems.com
Security reports: info@stockflowsystems.com
Address: StockFlow Systems, Belgium
Trusted by small businesses
What our customers say
“Super Kind! Quick replies from their support and very easy fixes, changed the dashboard a bit and customized it. Also gave me 450 items extra on the free plan just for me. Highly recommend and again great service!”
“Best customer service! Stockflow's customer support is fast and extremely helpful. They assisted me with customization of the software to improve my experience as a user.”