StockPortal.io — Privacy & Cookie Policy

Last updated: August 2026

This Privacy & Cookie Policy explains how R Brookes T/A StockPortal.io (“we”, “us”, “our”) handles personal data and cookies across our digital platforms, including our main website (stockportal.io), our standalone Stock Lookup Portals, and our Brand Resource Portals (collectively, the “Service”).

We are committed to protecting your privacy and complying strictly with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are & Data Controller

For the purposes of UK GDPR, the Data Controller responsible for your personal data is:

  • Legal Entity: R Brookes T/A StockPortal.io

  • Contact: Main Website Contact Form

2. Our Commitment to Data Minimisation

We operate on a strict data minimisation principle. Across all our services, we only collect the minimum amount of data required to deliver the platform to you.

A. Core Stock Lookup Portals

  • No Retail Data: We do not actively request, collect, or store personal details regarding your staff or retail customers.

  • Portal Logins: Login accounts are created entirely at your discretion and do not require real names or personal email addresses. If your team inputs personal details into these fields, we host them securely as a data processor, but we do not monitor or use this information.

  • Basic Activity Metrics: We track login counts and timestamps to provide account administrators with adoption statistics and maintain system security. We do not track individual browsing habits or store individual visitor IP addresses.

3. Personal Data We Collect & Why

We only collect personal data when you interact with us directly for business purposes:

  • Client Account & Billing Info (Name, business name, billing address, email address)

    • Purpose: Managing your subscription, account setups, and platform communications.

    • Lawful Basis (UK GDPR): Contractual Necessity

  • Payment Details

    • Purpose: Processing subscription payments via secure third-party processors (e.g., Stripe). We do not store full payment card details on our servers.

    • Lawful Basis (UK GDPR): Contractual Necessity

  • General Enquiries (Name, email address, message contents)

    • Purpose: Responding to sales, support, or technical queries sent via the website contact form.

    • Lawful Basis (UK GDPR): Legitimate Interests

  • Operational & Security Metadata (IP address, browser type, system logs)

    • Purpose: Maintaining platform security, preventing abuse or malicious links, and displaying basic link activity to account owners.

    • Lawful Basis (UK GDPR): Legitimate Interests

4. Cookies & Tracking Technologies

A cookie is a small text file placed on your device to help websites function efficiently.

  • Strictly Necessary Cookies: Our portals use temporary session cookies strictly necessary to authenticate admin/user logins and maintain secure navigation. These contain no personal information and are automatically deleted when you close your browser.

  • No Marketing Cookies: We do not use optional marketing, advertising, or invasive third-party tracking cookies across our stock or brand portals.

5. Data Security & Storage

  • Encryption: All login passwords and sensitive access tokens are heavily encrypted (hashed) before being stored in our database. We cannot view plain-text passwords.

  • Server Infrastructure: Our databases and website infrastructure are hosted on secure, enterprise-grade cloud servers located within the UK or European Economic Area (EEA).

  • Data Retention: We retain billing and administrative contact information for as long as is necessary to service your active account, comply with UK tax/accounting laws, or resolve business enquiries. Account and portal database records are removed immediately upon account cancellation or within 30 days maximum across routine system backup purges.

6. Sharing Your Data

We never sell, rent, lease, or trade your personal data or portal configurations to third parties. Data is shared exclusively with trusted sub-processors strictly to the extent required to operate the Service:

  • Hosting & Database Infrastructure: Cloud service providers (e.g., AWS, Vercel, Supabase)

  • Payment Gateways: Merchant payment processors (e.g., Stripe)

  • Transactional Email Services: Automated system notification providers (e.g., Postmark, SendGrid)

7. Your Rights Under UK GDPR

Under UK data protection law, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.

  • Right to Rectification: Request that we correct any inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): Request deletion of your account and personal data when you cancel your subscription.

  • Right to Restrict / Object: Object to or restrict certain processing activities.

To exercise any of these rights, please reach out using the contact form on our main website.

8. Contact & Regulatory Complaints

If you have any questions about this policy or wish to submit a data request, please submit a request via the contact form on our main website.

If you feel we have not handled your personal data correctly, you have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO).