BrainBox237
WorkServicesStudioStart a project
BrainBox237/Stocka/Privacy Policy

Stocka Privacy Policy

Last updated · 22 June 2026

On this page
  1. Overview
  2. Who we are
  3. Data we collect
  4. How we use it
  5. Legal bases
  6. Who processes it
  7. International transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Account & data deletion
  12. Children's privacy
  13. Changes
  14. Contact us

01 Overview

Stocka is an offline-first inventory and point-of-sale application for retailers and small businesses, published by BrainBox237 (“we”, “us”, “our”). This policy explains what information Stocka handles, why, where it goes, how long we keep it, and the choices and rights you have over it.

A core design principle of Stocka is that your business data lives on your device first. Stock, sales, debts and expenses are recorded and usable without any internet connection. Data only leaves your device for the specific purposes described below — mainly to sync, back up, license your app, and send notifications.

We do not sell your personal data, and we do not share your business records with advertisers. Stocka contains no advertising networks.

02 Who we are

Stocka is built and operated by BrainBox237, a software studio based in Cameroon. For privacy questions, you can reach us at privacy@brainbox237.com. For matters specific to Stocka, you can also use stocka@brainbox237.com.

We are the controller of the personal data described in this policy. The third parties listed in section 06 act as our processors and run the infrastructure that makes sync, storage and notifications work.

03 Data we collect

We collect only what Stocka needs to do its job. Depending on which features you use, this can include:

CategoryExamplesSource
Account & identityEmail address, display name, password (stored only as a secure hash), business profileYou, at sign-up
Business recordsProducts, prices, stock levels, sales, debts, expenses, suppliersYou, as you use the app
Customer detailsCustomer names and phone numbers you choose to save for debts and receiptsYou
Device contactsA contact you pick from your phone, only if you use the “add from contacts” optionYou, with permission
ImagesProduct and expense photos you attachYou
Device & technicalDevice identifier for licensing, app version, OS, push notification tokenAutomatically
Subscription & paymentPlan, status, and a payment reference from the payment provider (we do not store card or wallet credentials)Payment provider
DiagnosticsCrash reports and basic error logs, if enabledAutomatically

About your phone contacts

Stocka only reads your contacts at the moment you tap to add a customer from your phone book, and only the contact you select. We do not upload your whole address book, and we show a plain explanation before the system permission prompt appears. You can decline and still type customer details by hand.

04 How we use your data

  • To run the core app: recording and showing your stock, sales, debts and expenses.
  • To create and secure your account, and to recover access if you forget your password or PIN.
  • To sync your data across your devices and back it up to the cloud when you choose to.
  • To verify your subscription and keep your app licensed — including offline, using a signed licence stored on your device.
  • To send you notifications you have asked for, such as low-stock or sync alerts.
  • To provide support and to diagnose and fix crashes and bugs.
  • To meet legal, accounting and anti-fraud obligations.

We do not use your business records to build advertising profiles, and we do not sell them.

05 Legal bases

Where data-protection law requires a legal basis, we rely on: performance of our contract with you (running the app and your subscription); your consent (for optional things like contacts access and notifications, which you can withdraw); our legitimate interests (security, fraud prevention, and improving the app); and legal obligation (keeping certain payment and tax records).

06 Who processes your data

To deliver Stocka we rely on a small number of trusted infrastructure providers. They process data on our instructions only:

ProviderPurposeData involved
SupabaseAuthentication, cloud database, syncAccount, business and customer records
Cloudflare R2Image and backup storageProduct/expense images, backups
Firebase (Google)Push notificationsPush token, device identifier
NotchPayMobile Money & card subscriptionsPayment reference, plan, status

We declare each of these, and the data they handle, in the app’s store privacy disclosures. If we add or change a processor, we will update this list.

07 International transfers

Our providers may store and process data on servers outside Cameroon, including in the European Union and the United States. Where data crosses borders, we rely on the providers’ own safeguards and standard contractual protections to keep your information protected to a comparable standard.

08 How long we keep your data

  • Account & business data — for as long as your account is active.
  • Local data — stays on your device until you delete it or uninstall the app.
  • Backups — kept on a rolling basis and purged after deletion completes.
  • Payment & subscription records — retained for the period required by accounting, tax and anti-fraud law, even after account deletion. These records are kept to the minimum non-personal detail needed.
  • Diagnostics — kept for a short troubleshooting window, then deleted.

09 How we protect your data

We use encryption in transit, access controls on our cloud, and row-level security so that one business can never read another’s records. Your app licence is verified offline using a cryptographic (Ed25519) signature, so it cannot be forged on the device. Passwords are never stored in plain text.

No system is perfectly secure, but we work to industry practices and fix issues promptly. If a breach ever affects your personal data, we will notify you and the relevant authorities as required by law.

10 Your rights & choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or out of date.
  • Delete your account and associated data (see section 11).
  • Export a copy of your business data.
  • Object to or restrict certain processing, and withdraw consent.

To exercise any of these, email privacy@brainbox237.com. We respond within a reasonable time and at most within the period the law requires.

11 Account & data deletion

You can delete your Stocka account and its data at any time, either from inside the app (Settings → Account → Delete account) or from the web, without reinstalling the app, at brainbox237.com/stocka/delete-account.

When you delete your account, we remove:

  • Your authentication record and profile.
  • Your cloud database records and your membership of your business.
  • Your images and backups stored in the cloud.
  • Your registered devices and push notification tokens.

Some payment, licence and tax records are kept for the limited period the law requires, reduced to the minimum non-personal detail. If you own a business that has staff members, deleting your own account does not silently destroy their records — we will guide ownership transfer or shop closure first. Local data on your device is cleared when you delete in-app or uninstall.

12 Children’s privacy

Stocka is a business tool intended for adults running or working in a business. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has provided us data, contact us and we will remove it.

13 Changes to this policy

We may update this policy as Stocka evolves or the law changes. We will revise the “last updated” date above and, for significant changes, notify you in the app. Continuing to use Stocka after a change means you accept the updated policy.

14 Contact us

Questions, requests or complaints about privacy? Email privacy@brainbox237.com or write to BrainBox237, Buea, South-West Region, Cameroon. You also have the right to complain to your local data-protection authority.

BrainBox237

A software studio from Cameroon. Offline-first products for African markets, engineered to travel.

Studio
WorkServicesAboutContact
Stocka
Privacy policyTerms of serviceDelete account
Reach us
hello@brainbox237.com+237 0 00 00 00 00Buea · Douala, CM
© 2026 BrainBox237. All rights reserved.Built in 237 · Engineered offline-first