Privacy Policy
Effective date: 30 September 2026.
Introduction
This Privacy Policy explains how Stockily (‘Stockily’, ‘we’, ‘us’ or ‘our’) collects, uses, shares and protects personal data when you use Stockily, our subscription software platform for cash-on-delivery e-commerce, when you install the Stockily app, and when you visit our website at https://www.stockily.io (together, the ‘Service’).
Two roles apply. For the personal data of the people who hold Stockily accounts (merchants and their staff) and of visitors to our website, Stockily decides how and why the data is processed and is the controller. For the data that merchants store in Stockily about their own customers (buyers’ names, phone numbers, addresses, orders and calls), the merchant is the controller and Stockily is the processor: we process that data only to provide the Service to the merchant and on the merchant’s instructions.
At Stockily, access to a merchant’s data, including the data it stores about its customers, is limited to authorised staff, and only when this is needed to operate or secure the Service or to provide support, for example to look into an order that is stuck or a problem the merchant has reported.
Who we are and how to reach us
The Service is operated by Stockily. For any question about this policy, or to exercise your rights, contact us at contact@stockily.io. You can also message us on WhatsApp at +213 561 10 60 22. If you want to delete your account, the Account deletion page at https://www.stockily.io/en/legal/account-deletion describes the steps and what is deleted.
The data we collect about you
Account data. When you create an account we collect your e-mail address and a password (stored only as a hash by our authentication provider), the name of your company and of your shop, your country and currency, and your role. When an owner invites staff members, we store their name, e-mail address and role. We do not collect phone numbers, profile photos or a last-login time for account holders.
Security and usage records. Our servers record the actions taken in the Service (for example who changed an order, a role or a wallet balance, and when) in audit logs that merchants can consult for their own shops. To prevent abuse we record the IP address of sign-ups, of platform-administrator security events, and of storefront orders. Inside the app we run no analytics, crash reporting or advertising trackers.
Cookies and browser storage. The app keeps your session and your preferences (language, theme, the shop you last opened) in your browser’s local storage, not in cookies. Our website sets a language cookie and, if you arrived through a partner link, referral cookies for 90 days. Optional website analytics run only if you opt in through the consent banner. Our Cookie Policy lists every cookie.
Billing records. When you subscribe we record your plan, its dates and status, and the reference of each payment. When card payments are enabled they are processed by Stripe on Stripe’s own pages; we never receive, transmit or store card numbers. For payments recorded by our team we store only the reference and payment method you told us about.
Partner program. If you join our affiliate program we store your application, the details of the account we pay commissions to (account holder, identifier and bank name), your payout history, and, for each visitor who follows your link, a one-way hash of their IP address, their browser type, referrer and country.
Images and AI content. Product photos, storefront logos and the images or texts generated with the AI features (including the prompts you typed) are stored so that you can use them in your storefronts.
The data merchants store about their customers
Stockily is a tool merchants use to manage cash-on-delivery orders. To do so, merchants record their customers’ names, phone numbers, delivery addresses (wilaya, commune and address), order contents and amounts, delivery notes and the outcome of confirmation calls (the agent’s notes and the call result; no recordings). Orders that arrive from a connected sales platform (Shopify, WooCommerce, YouCan, Google Sheets or the merchant’s own system) are stored as received, including the full order data the platform sent.
Stockily builds a customer profile per phone number for each company: order history and reliability indicators such as cancellation and return rates, which help the merchant decide how to handle new orders. These profiles are visible only inside that company.
Storefronts. When a buyer orders on a merchant’s Stockily storefront, we record the order together with the buyer’s IP address, browser type, referrer and campaign tags, and we check the order with Cloudflare Turnstile to block bots. A buyer’s name and phone number typed into the order form are saved as an abandoned checkout as soon as a complete phone number has been entered, even if the order is never submitted, so that the merchant can follow up by phone.
This data belongs to the merchant. Buyers who want their data corrected or deleted should contact the merchant they bought from; we assist merchants with such requests.
How we use personal data
We use personal data to provide and operate the Service; to create and secure accounts and enforce access rights; to detect and prevent fraud and abuse (rate limits, bot checks, reliability indicators); to provide support and answer requests; to send service messages (for example partner-program e-mails and the answer to a contact-form message); to bill subscriptions; to improve and maintain the Service; and to meet our legal obligations.
We do not sell personal data, we do not use merchants’ customer data for our own marketing, and we do not use any data stored in Stockily to train artificial-intelligence models.
AI features
When a merchant asks the Service to write storefront copy, we send the product name, image and the merchant’s hints to Anthropic, which generates the text. When a merchant generates images, we send the merchant’s prompt and settings to fal.ai. No customer data is sent to either provider, and the use of each provider is subject to that provider’s own terms.
Legal bases
Where the EU or UK General Data Protection Regulation applies, we process account and billing data to perform our contract with you; security records, fraud prevention and service improvement on the basis of our legitimate interests, balanced against your rights; billing records to comply with legal obligations; and optional analytics on the basis of your consent, which you can withdraw at any time. Merchants’ customer data is processed on the merchant’s instructions under our contract with the merchant.
California residents have the right to know, access, correct and delete their personal information and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising. To exercise these rights, contact us at contact@stockily.io.
Who receives personal data
We share personal data only with providers that help us run the Service, under contracts that limit what they may do with it, and with third parties that a merchant chooses to connect. Our Sub-processors page lists them; the main ones are:
Supabase — database, authentication and file storage for all account and business data. Vercel — hosting, and the custom domains merchants attach to their storefronts. Cloudflare Turnstile — bot checks on sign-up and on storefront orders (receives the check token and the visitor’s IP address). Resend — delivery of the e-mails we send (partner-program messages, contact-form messages to our support inbox). Anthropic and fal.ai — the AI features described above. Stripe — card payments, when enabled (receives the account e-mail and the plan).
Couriers chosen by the merchant — Yalidine, ZR Express and Ecotrack receive the recipient’s name, phone number, address, the product list and the amount to collect when the merchant dispatches a parcel through Stockily. Meta (Conversions API) and TikTok (Events API) — only when a merchant enables them for a shop, we send order events with hashed contact details and the buyer’s IP address and browser type for the merchant’s advertising measurement. WhatsApp Business (Meta) — optional; when a merchant configures it, a message announcing the confirmation call is sent to the buyer’s phone. WhatsApp also carries the messages you send us if you contact us there. Connected sales platforms (Shopify, WooCommerce, YouCan, Google Sheets) send orders to Stockily; we do not send customer data back to them.
We may also disclose data when the law requires it, to protect our rights and those of our users, or as part of a merger, acquisition or sale of assets, with notice where the law requires it.
International transfers
Stockily serves merchants in Algeria and neighbouring markets. Our providers operate in the European Union and the United States, so personal data may be stored and processed outside your country. Where the law requires it, transfers are covered by appropriate safeguards such as standard contractual clauses.
How long we keep data
Account data is kept for as long as the account exists. You can request the deletion of your account at any time, in the app under Settings, Account, or by e-mail from the account’s address; deletion is completed within 30 days. The Account deletion page describes what is deleted and what must be kept.
Subscription and payment records are kept after deletion for as long as tax and accounting law require. Security and audit logs are kept for as long as they are needed to investigate fraud, abuse and disputes. Merchants’ customer data is kept until the merchant deletes it or deletes the company. IP addresses recorded for security and rate limiting are kept for as long as they are needed for those purposes.
Security
Every connection to the Service is encrypted in transit (HTTPS with HSTS). Each merchant’s data is isolated by row-level access rules enforced in the database and re-checked in every privileged operation, with automated tests for cross-tenant isolation. Passwords are handled by Supabase Auth and stored only as hashes; the credentials of connected sales platforms are encrypted at rest; verification tokens and recovery codes are stored as hashes; multi-factor authentication protects platform-administrator access. Sign-up and storefront orders are protected by Cloudflare Turnstile and rate limits.
No system is perfectly secure. If we learn of a personal-data breach that affects you, we will inform you and, where required, the competent authorities.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on it. To exercise these rights, contact us at contact@stockily.io; we may need to verify that the request comes from the account holder. Merchants can correct or delete most of their own customers’ data directly in the Service.
Subscriptions. Every new shop starts on the Free plan, with no card and no time limit. Paid plans are billed monthly by card, in US dollars, and renew automatically until you cancel; in Algeria they can also be paid by bank transfer, CCP or BaridiMob, in Algerian dinars, for a month or a year, without automatic renewal. You can cancel a card plan at any time from the billing portal in your account or by contacting us at contact@stockily.io; your access continues until the end of the period you have paid for.
If you believe we have not handled your data properly, you can complain to your data-protection authority. We would appreciate the chance to resolve the matter first.
Children
Stockily is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has given us personal data, contact us at contact@stockily.io and we will delete it.
Changes to this policy
We may update this policy. If the changes are material we will tell you by e-mail or in the Service before they take effect. The effective date at the top of the page shows when the current version began to apply.
Contact
For any question, request or concern about this policy or about how we handle personal data, write to Stockily at contact@stockily.io.