Privacy

Your data, your decisions.

We only ask for the data Stokis needs to forecast inventory, draft purchase orders, and keep the procurement trail clear.

Last updated6 May 2026
01

Overview

Stokis is an inventory and procurement agent. We connect to commerce, ERP, mail, and supplier systems to forecast demand and draft purchase orders.

The short version
We use your data to run Stokis for your workspace, protect the service, and improve product reliability. We do not sell your operational data.
02

Data we collect

We collect the information needed to create accounts, connect stores, forecast inventory, and prepare supplier communications.

CategoryExamplesPurpose
Account dataName, email, role, company, workspaceCreate accounts and secure access
Operational dataSKUs, stock levels, sales velocity, supplier rules, purchase ordersForecast demand and draft purchase orders
Communication dataSupplier emails, PO replies, delivery notes, read receiptsTrack confirmations and surface delays
TelemetryPages visited, actions taken, errors, device and browser dataImprove reliability and diagnose issues

Payment details are handled by our billing provider. We do not store full card numbers on Stokis systems.

03

How we use data

Your data is used to operate Stokis for your workspace: sync inventory, forecast demand, score supplier options, draft purchase orders, send approved supplier messages, and keep an audit trail.

  • Authenticate users and enforce workspace permissions.
  • Generate forecasts, reorder suggestions, and procurement drafts.
  • Send transactional emails and supplier communications you approve or configure.
  • Measure product reliability and investigate abuse or security events.
Model use
Customer operational data is used to provide the service to that customer. It is not sold or used for third-party advertising.
04

Sharing and sub-processors

We share data only with the named sub-processors below, or when required by law. Each operates under contract and processes data only for the services they provide to us.

Sub-processorPurposeRegion
Stripe, Inc.Subscription billing, invoices, and payment processingEU / US
Anthropic, PBCProcurement-agent reasoning (Claude API). Workspace data is sent only when the agent runs; not used to train Anthropic models.US
The customer's own SMTP provider (BYO)Outbound supplier mail is sent through SMTP credentials the customer configures themselves. Stokis stores those credentials at-rest under AES-256-GCM encryption.Customer-elected
Postmark / Cloudflare Email RoutingInbound supplier replies routed to the workspace inboxEU / US
Coolify-hosted VPS infrastructureApplication, database, file, and backup hostingEU
Umami CloudCookieless, privacy-first product analytics — aggregate pageviews and activation events only. No cookies, no cross-site tracking, no personal profiles, no advertising.EU
SentryApplication error monitoring and diagnosticsEU

This list is the complete set of sub-processors that receive workspace data. We update it before adding new ones — material changes are announced in the changelog.

05

Cookies and local storage

Stokis uses cookies and local storage strictly to keep you signed in and to remember your in-app preferences.

TypeExamplesRequired?
AuthenticationSession cookie set by better-auth so you stay signed inYes — site won't work without it
PreferencesLocal storage for the active workspace, sidebar collapse state, command-palette historyNo — clearable from your browser without breaking the app

For product analytics we use Umami (see the sub-processors table) — it is cookieless, sets nothing on your device, and builds no personal profiles. We do not use advertising or cross-site tracking cookies. Adding any cookie outside the table above would update this section first.

06

Retention and deletion

We keep data for as long as your workspace is active, as long as needed to provide the service, or as required by legal, tax, security, and audit obligations.

Data typeTypical retention
Active workspace dataFor the lifetime of the workspace
Closed workspace dataHidden immediately on deletion, then permanently erased 30 days later (a recovery grace window), subject to legal holds
Audit logsRetained for security, compliance, and dispute records
TelemetryAggregated or deleted after it is no longer needed

You can request export or deletion by contacting info@stokis.io.

07

Your rights

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing of your personal data.

To exercise these rights, email info@stokis.io. We may need to verify your identity and workspace relationship before acting on a request.

08

Security

We use technical and organizational safeguards designed to protect customer data, including encrypted transport, role-based access controls, audit logs, and least-privilege operational access.

Security reports
If you believe you found a vulnerability, contact info@stokis.io. Please do not access or modify data that is not yours.
09

Contact