Legal
Privacy Policy
Last updated: 27 April 2026
This policy explains how StockSphere Ltd ("StockSphere", "we", "us") handles personal data when you visit our website, sign up for a free trial, or use the StockSphere platform.
1. Who we are
StockSphere Ltd is a company registered in England and Wales (company number 12345678), with a registered office at 1 Example Street, London, EC1A 1AA, United Kingdom. We are registered with the UK Information Commissioner's Office (registration number ZA000000) and act as the data controller for personal data we collect through our marketing site, and as a data processor for personal data our customers upload to the StockSphere platform.
Our Data Protection Officer can be reached at dpo@stocksphere.app.
2. The data we collect
2.1 Marketing site visitors
- Contact form submissions (name, work email, company, message).
- Trial sign-up details (email, name, company, role).
- With your consent: aggregated analytics about pages viewed and features clicked. We do not build advertising profiles.
- Strictly necessary cookies for security and load-balancing.
2.2 Platform users (operators, staff, client-portal users)
- Account details: name, work email, role, organisation.
- Authentication data: hashed password, multi-factor secrets.
- Audit logs: sign-ins, security-relevant actions, IP, user agent.
- Operational data your organisation chooses to store (customers, warehouses, inventory, shipments). This is processed on behalf of your organisation as the controller.
3. How we use your data
- To provide and secure the StockSphere service.
- To verify identity, prevent fraud and comply with legal duties.
- To respond to support and sales enquiries.
- With your consent, to measure how the marketing site is used and to improve it.
- To send service-related notifications you have not opted out of.
4. Legal bases (UK & EU GDPR)
- Contract: providing the StockSphere service to a paying customer or trial user.
- Legitimate interests: securing our service, preventing abuse, responding to enquiries.
- Consent: non-essential cookies and direct marketing to non-customers.
- Legal obligation: tax, accounting, lawful disclosure requests.
5. Sharing
We never sell your personal data. We share it only with sub-processors who help us run the service (cloud hosting, email delivery, error monitoring, payment processing). All sub-processors are bound by written data-processing agreements and process data only on our documented instructions.
6. International transfers
Where personal data leaves the UK or EEA, we rely on the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or an adequacy decision, and we apply supplementary technical and organisational measures including encryption in transit and at rest.
7. Retention
- Marketing enquiries: 24 months from last contact.
- Platform account data: for the life of the account, then deleted within 30 days of closure (audit logs retained up to 12 months for security investigations).
- Billing records: 7 years (UK statutory).
8. Your rights
Under UK GDPR and EU GDPR you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time. Under the California Consumer Privacy Act, California residents additionally have the right to know what is collected, to delete, to correct, and to opt out of "sale" or "sharing" — we honour Global Privacy Control signals automatically.
To exercise any right, email privacy@stocksphere.app. We will respond within one calendar month. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
9. Security
StockSphere is hosted on infrastructure with ISO 27001 / SOC 2 controls. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production data is role-gated and audited. We support multi-factor authentication for all accounts and enforce it for administrators.
10. Children
StockSphere is not intended for anyone under 16.
11. Changes
We will post material changes to this policy at this URL with at least 30 days' notice for existing customers.
12. Contact
Privacy queries: privacy@stocksphere.app
Data Protection Officer: dpo@stocksphere.app