Privacy Policy
Last updated: July 14, 2026
The StokBox platform is operated by Inbanitori Hub (company no. 208348524), Ben Yehuda St., Tel Aviv ("we", "us", or "our"), including integrations with Shopify, Wix, WooCommerce, Caspit and other services. This Privacy Policy explains how we collect, use, and protect your information, and is intended to comply with the Israeli Privacy Protection Law, 1981, including Amendment 13 (in force August 14, 2025).
1. Information We Collect
We collect the following categories of information:
- Account data — your name, email address, password, and organization details. If you sign in with Google, we receive your Google profile (name, email, avatar).
- Store & integration data — product information, inventory levels, orders, locations, and basic store details from connected platforms.
- Data you enter about third parties — details of your own customers and suppliers (name, contact person, phone, email, address, and supplier bank details). You are responsible for having a lawful basis to provide this data to us.
- Documents you upload — invoices and delivery notes you submit for automatic extraction (OCR).
- Technical data — IP address, device and browser information, and error logs, collected for security and troubleshooting.
- Support data — screenshots you submit with a bug report.
2. How We Use Your Data
- Providing the service, synchronizing inventory, and displaying your data in the dashboard
- Generating analytics and stock alerts, and matching barcode scans to your products
- Extracting data from documents you upload (OCR)
- Securing the service, preventing abuse, and troubleshooting errors
- Sending transactional email (team invitations, scheduled reports)
We do not use your data for advertising or marketing.
3. Lawful Basis for Processing
Under Israeli law we rely on the following bases (Israeli law does not recognize "legitimate interest" as a basis):
- Performance of a contract — providing your account, integrations, OCR, dashboards, and transactional emails.
- Legal obligation — security logging, access controls, and IP retention required under the Privacy Protection (Data Security) Regulations, 2017.
- Consent — where you explicitly opt in to an optional feature.
Where you enter data about your own customers or suppliers, you are the controller of that data and responsible for its lawful basis; we process it as a processor on your behalf.
4. Data Storage & Security
All data is stored in encrypted databases on secure cloud infrastructure. We use encryption at rest and in transit (TLS 1.2+), row-level security for complete tenant isolation, and restrict access to production data to authorized personnel only.
5. Third Parties & Processors
We do not sell, rent, or trade your data. To operate the service we use trusted processors who handle data on our behalf under data processing agreements:
- Supabase / Amazon Web Services — database, authentication, and file storage
- Vercel — application hosting and content delivery
- Google Cloud (Vision API & Gemini) — text extraction (OCR) from documents you upload
- Google — sign-in (OAuth) when you choose Google login
- Sentry — error and performance monitoring (may include IP address)
- Resend — sending transactional email
- Inngest — background job processing
Connected stores (Shopify, Wix, WooCommerce, Caspit) exchange data with us at your instruction. We may also disclose data if required by law or to protect our legal rights.
6. International Transfers
Some of our processors are located outside Israel (primarily the United States and the European Union). When your data is transferred abroad it is done under data processing agreements and safeguards consistent with the Privacy Protection Law. These transfers are necessary to provide the service.
7. Data Retention & Deletion
- Account & store data — retained while your account is active; permanently deleted within 30 days of account deletion.
- Uploaded documents (OCR) — source files deleted within 30 days.
- Bug-report screenshots — deleted within 90 days.
- Security logs (failed-login IPs) — cleared on successful login.
You may request immediate deletion at any time by contacting us.
8. Your Rights (Amendment 13)
You have the following rights over your personal data:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Restriction — request that we restrict processing of your data
- Objection — object to processing of your data
- Portability — receive your data in a structured format
To exercise any of these rights, contact us at the address below. We will respond within 30 days. You also have the right to lodge a complaint with the Israeli Privacy Protection Authority (PPA).
9. Cookies
We use essential cookies only for authentication and session management. We do not use tracking cookies or third-party analytics cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification.
11. Contact Us
For any question about this Privacy Policy or your data, contact us at:
Inbanitori Hub (company no. 208348524)
Ben Yehuda St., Tel Aviv
Email: goomidigital@gmail.com