Privacy policy
1. Controller
[FULL LEGAL NAME/COMPANY]
[ADDRESS]
Email: support@stockora.de
2. Scope
This policy describes processing on stockora.de, in the Stockora app, and through api.stockora.de and auth.stockora.de.
3. Website access
IP address, timestamp, requested resource, referrer, browser information, and response status may be processed in server logs to provide the website securely and reliably. The initial landing page uses no advertising or analytics cookies.
4. Account and authentication
Registration and login require an email address, encrypted password hash, verification state, security tokens, and timestamps. Passwords are not stored in plain text.
5. App data
Depending on the features used, we process profile information, shopping lists, items, quantities, group membership, activities, store planning, pantry spaces, stock levels, reminders, product mappings, and optional profile emoji.
6. Nutrition and health features
Stockora may calculate general nutrition or quality summaries from purchases and voluntary settings. These do not replace medical advice. Where information qualifies as health data, explicit consent and a withdrawal mechanism must be provided before production use.
7. Shared groups
Members of shared groups may see display name, profile emoji, added items, and list-related activity. Users are informed about this visibility before sharing.
8. Product sources
Product details may come from our database and open sources such as Open Food Facts. Requests are made without user identity where possible. External information may be incomplete or inaccurate.
9. AI-supported features
When optional recipe or assistant functions are used, selected pantry and product information may be sent to an AI provider. Email addresses, passwords, and unnecessary identifiers should not be transmitted. Before launch, specify provider, processing location, legal basis, international transfer safeguards, and data processing agreement: The OpenAI API is used. For customers in the EEA, the contracting party is generally OpenAI Ireland Ltd. Processing is governed by the applicable business terms and data processing agreement. Where processing occurs outside the EEA, the safeguards provided in that agreement, including Standard Contractual Clauses, apply. Before public launch, the operator must execute the DPA in the account and document the configured API data-retention setting..
10. Transactional email
Registration, password reset, and account deletion emails are delivered through STRATO. Recipient address, sender details, delivery metadata, and message content are processed for this purpose.
11. Hosting
The public website is hosted by STRATO. API and database operate on separate infrastructure in STRATO AG in Germany. Required processor agreements are concluded with service providers.
12. Retention
Data is retained only as long as required for its purpose or by law. Verification, reset, and deletion tokens expire automatically. Server logs are deleted after 14 days. Personal account data is removed after deletion unless legal retention obligations apply.
13. Account deletion
Delete your account in the app or at auth.stockora.de/public/auth/delete-account. Web deletion requires email confirmation. Shared lists can remain available to other members while the deleted account’s personal attribution is removed or transferred.
14. Your rights
Subject to applicable law, users have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Users may also lodge a complaint with a competent data protection authority.
15. Contact and changes
Send privacy requests to support@stockora.de. This policy will be updated when features, providers, or legal requirements change.