Privacy Policy
Last updated: July 20, 2026
Stockroom, Inc. (“Stockroom”, “we”, “us”) provides inventory and sales management software. This policy explains what data we hold, why we hold it, who else can see it, and the choices you have. It describes how the product works today rather than what we might do later.
Information we collect
- Account details you provide: your name, email address (or an employee ID for staff accounts created for you by your organization), the organization you belong to, and your role and location permissions within it.
- Business records you enter or import: products, variants, stock movements, suppliers, purchase orders, customers, sales orders, payments, audits and the reports derived from them. Customer records you store are your data about your customers, held on your behalf.
- Uploaded files, currently product images, stored on the server that runs the service.
- Integration data you authorize us to sync, described below.
- An activity log of significant actions taken inside your organization (who changed what and when), visible to your own administrators.
- Diagnostic data when something breaks, described under “Error reports”.
How we use it
We use your data to operate the service, provide support, keep your workspace secure, bill you correctly, and fix problems. We do not sell your data and we do not use your business records to advertise to you. Every organization's data is isolated by per-tenant scoping enforced on every database query.
Square
Connecting Square is optional and the product works fully without it. When you connect it, you grant access through Square's own consent screen and we store the resulting access and refresh tokens encrypted at rest. We then sync only the areas you enable: catalog, customers, inventory, orders, refunds, payouts, disputes, gift cards and card-reader checkouts. You choose the direction of each area, and you can disconnect at any time from the integrations settings, which revokes our access.
Payments and billing
Subscription billing is handled by Stripe. Card details are entered on Stripe's own checkout and are never sent to or stored by us: we keep only the subscription identifiers, plan, status and billing period Stripe reports back. Payments you take from your own customers are processed by your own provider, such as Square, and never pass through us.
Transactional email (invitations, alerts, support replies) is sent through Microsoft Graph from a mailbox we control. If you submit a support or feature request from inside the app, the message, your identity and the page you were on are emailed to our internal mailbox so we can answer you.
Error reports
When the application throws an unexpected error we record the message, the stack trace, and where possible the organization and user it happened for, so we can find and fix it. Those reports are scrubbed before they are stored: database URLs, access tokens, authorization headers, API keys and email addresses are redacted, and repeated occurrences of the same fault collapse into a single record rather than accumulating copies.
Analytics
This marketing website runs no analytics and no third-party scripts at all. Inside the product app we may run Microsoft Clarity to understand how the interface is used; where enabled it is configured to mask page content so your business records are not captured.
Support access to your workspace
Our support staff can open your organization to diagnose a problem you have raised. This is deliberately not invisible: every such session is recorded in your own organization's activity log, and any change made during one is attributed to the member of our staff who made it, not to you.
Where your data lives, and backups
Your data is held in a PostgreSQL database on servers we operate. We take nightly backups, keep a retained history of them, and copy them to separate storage so a single machine failing does not lose your records. Backups inherit the same access restrictions as the live database.
Retention and portability
Your data remains yours. You can export your lists and reports to CSV at any time without asking us. If you cancel, your records are retained so you can return or export them; you may request deletion of your organization's data by contacting us. Note that moving to a smaller plan deactivates records rather than deleting them, so nothing is lost and everything can be restored if you move back up.
Security
Traffic is served over HTTPS. Passwords and override codes are stored only as salted hashes, never in a form we can read back. Integration tokens are encrypted. Access within an organization is limited by role and by location. No system is perfectly secure, but we work to limit exposure and to respond quickly to any incident.
Contact
Questions about privacy, or a request about your data? Email help@stockroom-ims.com. It is the only address we monitor for help.