How StockSafe handles your information.
Last updated: August 13, 2026
StockSafe is published by Nextgen Wellness LLC, a Florida limited liability company ("we", "our"), which provides inventory compliance software to small businesses. This Privacy Policy describes what information we collect, how we use it, and the limited circumstances under which we share it. By creating an account, you agree to the practices described here.
Information we collect
- Account information: your name, email address, organization name, role, and (if you opt in to SMS) your mobile phone number.
- Inventory data: products, quantities, expiry dates, suppliers, purchase orders, and any notes you enter into the application.
- Files you upload: photos of shelves and supplier invoice PDFs, when you choose to use an AI feature that reads them. See "AI features" below for what happens to them.
- Authentication data: a hashed password (never stored in plaintext) and JSON Web Tokens for session management.
- Billing information: your subscription tier and Stripe customer/subscription IDs. Card numbers and payment details are handled directly by Stripe and never touch our servers.
- Operational logs: request logs (IP, path, status code) for debugging and abuse detection; error reports when something breaks; SMS audit records for the messages we send on your behalf.
- Free tool submissions: if you download the DEA biennial inventory worksheet without an account, we keep the email address and pharmacy details you typed so we can send the occasional compliance tip. Your DEA registration number is the exception: it is printed onto your worksheet and is never saved, logged, or emailed to us.
How we use your information
- Provide the StockSafe service — alerts, reports, purchase orders, dashboards.
- Send transactional emails and (only with your opt-in) SMS messages about your inventory.
- Process subscription payments via Stripe.
- Diagnose bugs, investigate abuse, and improve the product.
We do not sell your data, share it with advertisers, or use it for marketing by third parties. We do not target ads to you based on your inventory or account activity.
AI features
Several optional features use Anthropic's Claude models: building a starting product catalog from a description you type, suggesting defaults for a new product, reading a photo of a shelf, and matching a supplier invoice to a purchase order.
- We send only what the feature needs: the text you typed, or the file you chose to upload. We do not send your staff records, your customer information, or your full inventory.
- Nothing you enter is used to train an AI model. Anthropic processes these requests on our instructions.
- Uploaded photos and invoices are stored only for the seconds it takes the model to read them, and are deleted immediately afterwards. We do not keep the file or a link to it.
- Every AI result is a suggestion you review. Nothing is written to your records until you confirm it.
- These features are optional. StockSafe works without them.
Notes that name a person are refused, not sent. The adjustment note is a free-text box, so somebody will eventually type a patient name into it. Before any note is sent for parsing, the server checks it and refuses if it looks like it contains a name, a date of birth, a phone number, an email address, or a record number. It refuses rather than editing the note, because the identifier a filter misses is the one that would have mattered. The note itself still saves to your own records, which is where it belongs. If you would rather no note ever left your account, ask us to turn the AI features off for your organization.
Third-party processors we rely on
To operate StockSafe we share the minimum necessary information with the following processors:
- Supabase (PostgreSQL hosting): stores your account and inventory data.
- Railway and Vercel: application hosting.
- Anthropic: the AI features described above.
- Vercel Blob: holds an uploaded photo or invoice for the seconds the AI needs to read it, then it is deleted.
- Stripe: subscription billing and payment processing.
- Resend: transactional email delivery (alerts, password resets, purchase orders).
- Twilio: SMS delivery for opted-in alerts and purchase order notifications.
- Cloudflare: the bot check on the signup form. It sees your IP address and browser signals, not your data.
- CloudMailin: receives email sent in to StockSafe and passes it to the application.
- Sentry: error reports when the application breaks. Configured not to attach personal information.
- Google: "Sign in with Google", if you choose to use it. We receive your identity, never your Google password.
- UPCitemdb: barcode-to-product lookups (only the scanned barcode is sent).
We do not run advertising trackers, analytics pixels, or session-replay tools, and the web fonts are served from our own domain rather than a font CDN, so no third party is told which pages you read.
A fuller description, including what each processor stores and where, is on the Security page.
SMS-specific notice
If you opt in to SMS alerts, your mobile number is used solely to deliver transactional notifications related to your inventory and purchase orders. We will not send marketing or promotional SMS. Message frequency depends on your inventory activity — typically up to one alert digest per day, plus per-event purchase order messages when an admin chooses SMS as the delivery channel.
Message and data rates may apply. Your mobile carrier may charge you for messages sent or received. Reply STOP to any message to opt out, or HELP for assistance. You can also disable SMS alerts at any time from Settings in the StockSafe application.
Cookies and what is stored in your browser
StockSafe does not use advertising cookies, analytics cookies, or tracking pixels, and there is no consent banner because there is nothing to consent to.
The application keeps a few things in your browser's local storage so it works: your sign-in token, which is what keeps you logged in and is cleared when you sign out; your light or dark theme choice; and small interface preferences such as which columns you sorted by. These stay on your device. Clearing your browser data signs you out and resets those preferences, and nothing else is lost, because your records live on the server.
Cloudflare sets a short-lived cookie as part of the bot check on the signup form. That one is strictly necessary to tell a person from a script, and it carries no advertising identifier.
Data retention
We retain your account and inventory data for as long as your account is active, and for 30 days after a cancellation so you can come back without losing your history. After that we delete it, except where we are required to retain limited records for tax, legal, or fraud-prevention purposes (typically Stripe transaction records).
Files you upload for an AI feature are not retained at all. They are deleted as soon as the model has read them.
Your rights
You can:
- Access, correct, or export your data from the application.
- Delete your account and everything in it. Email support@getstocksafe.com from your account address. There is no delete button in the app yet, so this is done by hand within 7 business days, and you get a confirmation when it is finished.
- Revoke SMS consent by un-checking the toggle in Settings or replying STOP to any message.
- Request a copy of the personal data we hold by emailing support@getstocksafe.com.
If you are a resident of the EU, UK, or California and wish to exercise rights under GDPR or CCPA, please contact us at the email above.
Children's privacy
StockSafe is a B2B service intended for use by businesses and their employees. We do not knowingly collect information from anyone under 16. If you believe a minor has provided us with personal information, contact us and we will delete it.
Security
We use industry-standard practices: TLS in transit, hashed passwords (bcrypt, 12 rounds), JWT-based authentication, per-tenant data isolation enforced server-side, and least-privilege access to our hosting providers. No system is perfectly secure; we will notify affected users in the event of a confirmed breach of personal data, in accordance with applicable law.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice prior to taking effect. The "Last updated" date at the top reflects the most recent revision.
Contact
Questions, requests, or complaints about your data? Email us at support@getstocksafe.com.