Stok Privacy Policy

Effective date: August 24, 2026

This Privacy Policy explains how SelfAwareTech collects, uses, stores, and protects information when you use the Stok mobile and web applications ("Stok"). The mobile app works locally without an account. Users who create an account can securely synchronize authorized shop records across mobile, web, and other signed-in devices.

1. Information stored on your device

These records are stored on your device first so Stok continues to work offline.

2. Automatic cloud synchronization

When internet is available, Stok sends the latest business snapshot to SelfAwareTech for recovery support and aggregate product, stock, sales, pricing, profit, and regional market analytics. A snapshot can include shop names, user-confirmed town and county, permission-based approximate device location, product and stock records, purchase and sale history, currency, country, locale, and timezone.

Account synchronization is separate from the pseudonymous analytics snapshot. When a user signs in, Stok stores the shops, products, and transaction records that account is authorized to use. Access is enforced per shop: an account may be an owner in one shop and an employee in another. Employee responses exclude owner-only cost, profit, supplier, and unrelated transaction information. The phone keeps a local copy for offline operation and reconciles queued changes after connectivity returns.

3. How we use information

Measured records are not presented as forecasts, and SelfAwareTech does not use the admin dashboard to identify individual people.

4. Data sharing

We do not sell personal information. We may share information only with trusted service providers that support hosting, analytics, security, and customer support under contractual confidentiality obligations, or when required by law.

5. Retention, deletion, and de-identification

Stok keeps one latest analytics snapshot per pseudonymous install. Signed-in operational records are retained while the account or shop relationship remains active and as reasonably necessary for security, legal, and recovery needs. On a valid deletion request, SelfAwareTech deletes or de-identifies the relevant raw backup and identifying or linkable fields, subject to legal and fraud-prevention obligations. Non-identifying facts about places, goods, stock, quantities, prices, and activity may be retained in de-identified or aggregate form for historical analytics and privacy-preserving AI research. Access secrets and direct contact details are not retained for those purposes.

We apply access controls, encryption in transit, server-only credentials, rate limits, and administrator MFA. No security control removes all risk.

6. Your choices and rights

7. Children

Stok is not intended for children under 13. We do not knowingly collect personal data from children under 13.

8. Policy updates

We may update this policy from time to time. The latest version will always be available on this page with the updated effective date.

9. Contact

For privacy questions or data requests, contact: support@selfawaretech.com

Company: SelfAwareTech
Location: Nairobi, Kenya
Website: www.selfawaretech.com