Stok Privacy Policy
This Privacy Policy explains how SelfAwareTech collects, uses, stores, and protects information when you use the Stok mobile and web applications ("Stok"). The mobile app works locally without an account. Users who create an account can securely synchronize authorized shop records across mobile, web, and other signed-in devices.
1. Information stored on your device
- Shop names and locations, currencies, products, categories, descriptions, stock levels, and low-stock settings.
- Purchases, sales, prices, profit, inventory activity, and their dates.
- Local owner/employee access settings and a hashed owner PIN where you enable that feature.
- For signed-in use: email address, authentication records, display name, per-shop owner or employee membership, and security/session metadata handled by our authentication provider.
These records are stored on your device first so Stok continues to work offline.
2. Automatic cloud synchronization
When internet is available, Stok sends the latest business snapshot to SelfAwareTech for recovery support and aggregate product, stock, sales, pricing, profit, and regional market analytics. A snapshot can include shop names, user-confirmed town and county, permission-based approximate device location, product and stock records, purchase and sale history, currency, country, locale, and timezone.
- Owner/employee access profiles, PIN hashes, backup credentials, install IDs, email addresses, and phone numbers are excluded or stripped before the backup is stored.
- A pseudonymous install reference is stored so a later backup can replace the earlier snapshot.
- Your IP address is used transiently for abuse rate limiting; only a keyed hash is stored for that purpose.
- The MFA-protected administrator dashboard may show the shop name entered by the user and broad business location. It does not receive access secrets or direct personal contact fields.
Account synchronization is separate from the pseudonymous analytics snapshot. When a user signs in, Stok stores the shops, products, and transaction records that account is authorized to use. Access is enforced per shop: an account may be an owner in one shop and an employee in another. Employee responses exclude owner-only cost, profit, supplier, and unrelated transaction information. The phone keeps a local copy for offline operation and reconciles queued changes after connectivity returns.
3. How we use information
- Provide automatic backup and recovery support when the device is online.
- Authenticate users, synchronize authorized shops across devices, and administer per-shop owner and employee access.
- Understand product adoption, inventory patterns, common goods, stock risk, and geographic demand.
- Improve reliability, capacity planning, fraud protection, and future privacy-preserving AI features.
Measured records are not presented as forecasts, and SelfAwareTech does not use the admin dashboard to identify individual people.
4. Data sharing
We do not sell personal information. We may share information only with trusted service providers that support hosting, analytics, security, and customer support under contractual confidentiality obligations, or when required by law.
5. Retention, deletion, and de-identification
Stok keeps one latest analytics snapshot per pseudonymous install. Signed-in operational records are retained while the account or shop relationship remains active and as reasonably necessary for security, legal, and recovery needs. On a valid deletion request, SelfAwareTech deletes or de-identifies the relevant raw backup and identifying or linkable fields, subject to legal and fraud-prevention obligations. Non-identifying facts about places, goods, stock, quantities, prices, and activity may be retained in de-identified or aggregate form for historical analytics and privacy-preserving AI research. Access secrets and direct contact details are not retained for those purposes.
We apply access controls, encryption in transit, server-only credentials, rate limits, and administrator MFA. No security control removes all risk.
6. Your choices and rights
- You can deny location permission and select the business county and town manually.
- You can request access, correction, export, de-identification, or deletion by contacting us with information sufficient to locate the relevant shop record.
- Shop owners can add or remove employee access. Removing a membership stops that account from opening the shop on future sync.
- Deleting the app or clearing its local storage removes the local copy and may also remove the reference needed to locate a server backup; contact us first if you want a server-side request handled.
7. Children
Stok is not intended for children under 13. We do not knowingly collect personal data from children under 13.
8. Policy updates
We may update this policy from time to time. The latest version will always be available on this page with the updated effective date.
9. Contact
For privacy questions or data requests, contact: support@selfawaretech.com
Company: SelfAwareTech
Location: Nairobi, Kenya
Website: www.selfawaretech.com