Privacy policy for Stockpilot
Privacy Policy
Stockpilot is committed to protecting the privacy of our users. This policy explains what personal data we collect, why we process it, on what legal basis, how long we keep it and who we share it with.
Stockpilot is a registered trade name of Jiyu Ninja B.V., registered with the Dutch Chamber of Commerce under number 83679723 and VAT number NL862955919B01, Vredenburg 40, 3511 BD Utrecht, the Netherlands. Contact: info@stockpilot.com.
Stockpilot is a registered trade name of Jiyu Ninja B.V., registered with the Dutch Chamber of Commerce under number 83679723 and VAT number NL862955919B01, Vredenburg 40, 3511 BD Utrecht, the Netherlands. Contact: info@stockpilot.com.
1. Two roles
We act in two different roles.
As controller for personal data relating to you as our customer and to the users of your account. Articles 2 to 9 of this policy apply to that processing.
As processor for personal data of your own customers that passes through Stockpilot from your webshop and marketplace channels. You are the controller for that data. Article 10 applies, alongside our Data Processing Agreement.
As controller for personal data relating to you as our customer and to the users of your account. Articles 2 to 9 of this policy apply to that processing.
As processor for personal data of your own customers that passes through Stockpilot from your webshop and marketplace channels. You are the controller for that data. Article 10 applies, alongside our Data Processing Agreement.
2. Data we collect as controller
Account and contact data: name, business name, email address, telephone number, address, Chamber of Commerce and VAT number, customer number.
Billing data: invoices, payment history, and payment details processed by our payment provider. We do not store full card numbers ourselves.
Support data: the correspondence you have with us, tickets and internal notes relating to your account.
Log data: IP addresses, browser versions and timestamps.
Usage data: features used, content viewed and actions performed in the application.
Anything else you choose to provide.
Billing data: invoices, payment history, and payment details processed by our payment provider. We do not store full card numbers ourselves.
Support data: the correspondence you have with us, tickets and internal notes relating to your account.
Log data: IP addresses, browser versions and timestamps.
Usage data: features used, content viewed and actions performed in the application.
Anything else you choose to provide.
3. Why we process it, and on what basis
Providing and maintaining the service: performance of the contract.
Account administration and service communication: performance of the contract.
Invoicing and payment collection: performance of the contract, and legal obligation for retention.
Customer support: performance of the contract.
Security, fraud prevention and troubleshooting: legitimate interest.
Analysing usage to improve the service: legitimate interest.
Newsletters and promotional content: consent, withdrawable at any time.
Account administration and service communication: performance of the contract.
Invoicing and payment collection: performance of the contract, and legal obligation for retention.
Customer support: performance of the contract.
Security, fraud prevention and troubleshooting: legitimate interest.
Analysing usage to improve the service: legitimate interest.
Newsletters and promotional content: consent, withdrawable at any time.
4. How long we keep it
Account and contact data: for the duration of the subscription, then 14 days for export, then deleted.
Invoices and financial records: 7 years, statutory fiscal retention.
Support correspondence and tickets: 24 months after the last contact.
Log data: 12 months.
Usage data: 24 months.
Marketing consent and opt-outs: until withdrawn, opt-out records retained.
Where a dispute or legal claim is ongoing, we may retain relevant data for as long as necessary to handle it.
Invoices and financial records: 7 years, statutory fiscal retention.
Support correspondence and tickets: 24 months after the last contact.
Log data: 12 months.
Usage data: 24 months.
Marketing consent and opt-outs: until withdrawn, opt-out records retained.
Where a dispute or legal claim is ongoing, we may retain relevant data for as long as necessary to handle it.
5. Who we share it with
We use the following categories of processors: hosting and storage, payment processing, customer support software, email delivery, analytics and error monitoring. The current list of named subprocessors is published at stockpilot.com/subprocessors.
We share data with the marketplaces, webshops, carriers and other platforms you connect yourself, to the extent needed to provide the service.
We disclose data where required by law or where necessary to establish, exercise or defend a legal claim.
We do not sell personal data.
We share data with the marketplaces, webshops, carriers and other platforms you connect yourself, to the extent needed to provide the service.
We disclose data where required by law or where necessary to establish, exercise or defend a legal claim.
We do not sell personal data.
6. Transfers outside the EEA
Some of our processors are established outside the European Economic Area. Where that is the case, the transfer takes place under the European Commission's standard contractual clauses or another valid transfer mechanism. The subprocessor list states, per processor, where processing takes place.
7. Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, access control on a need-to-know basis, logging and regular backups. No system is completely secure, and we do not guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to the persons concerned, we notify the Autoriteit Persoonsgegevens within 72 hours and inform the persons concerned where the law requires it.
In the event of a personal data breach that is likely to result in a risk to the persons concerned, we notify the Autoriteit Persoonsgegevens within 72 hours and inform the persons concerned where the law requires it.
8. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict processing, to object to processing based on legitimate interest, and to data portability. Where processing is based on consent, you can withdraw that consent at any time.
Requests can be sent to info@stockpilot.com. We respond within one month. Where a request is complex, we may extend that by two months and will tell you so within the first month.
If you are not satisfied with how we handle your request, you can lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority.
Requests can be sent to info@stockpilot.com. We respond within one month. Where a request is complex, we may extend that by two months and will tell you so within the first month.
If you are not satisfied with how we handle your request, you can lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority.
9. Cookies
We use cookies and comparable techniques. Details are in our cookie policy.
10. Marketplace and channel data, our role as processor
When you connect a sales channel to Stockpilot, we retrieve order data from that channel on your behalf. That data contains personal data of your customers, such as name, delivery address, email address and telephone number. You are the controller, we are the processor.
We process this data only to provide the service and on your documented instructions, which means receiving, processing, fulfilling, shipping and returning orders and keeping stock in sync across your channels. We do not use it for any other purpose, we do not use it to build profiles across customers, and we do not sell it.
Our Data Processing Agreement governs this processing, including security measures, subprocessors, assistance with data subject requests, breach notification, and the return or deletion of the data at the end of the service. It is accepted when you create an account and is available at stockpilot.com/dpa.
At the end of the service you can choose between the return and the deletion of this data, as set out in the Data Processing Agreement.
We process this data only to provide the service and on your documented instructions, which means receiving, processing, fulfilling, shipping and returning orders and keeping stock in sync across your channels. We do not use it for any other purpose, we do not use it to build profiles across customers, and we do not sell it.
Our Data Processing Agreement governs this processing, including security measures, subprocessors, assistance with data subject requests, breach notification, and the return or deletion of the data at the end of the service. It is accepted when you create an account and is available at stockpilot.com/dpa.
At the end of the service you can choose between the return and the deletion of this data, as set out in the Data Processing Agreement.
11. Marketplace requirements, including the Amazon Data Protection Policy
Marketplaces impose their own binding requirements on how personal data from their platform may be handled. Where those requirements are stricter than this policy or the Data Processing Agreement, the marketplace requirements prevail and we apply them.
For personal data originating from Amazon, we comply with the Amazon Data Protection Policy and the Amazon Acceptable Use Policy. This means in particular:
Purpose limitation. Amazon personal data is used solely to fulfil orders placed through Amazon and to provide the service to you as the seller of record. It is not used for marketing, not enriched with data from other sources, not resold, and not shared with any party other than those needed to fulfil the order.
Retention and deletion. Amazon personal data is retained for no longer than 30 days after order delivery, after which it is permanently deleted, except where retention is required by law. Where retention is legally required, the data is archived in encrypted form, access is restricted to the personnel who need it for that legal purpose, and it is deleted once the legal retention period expires.
Encryption. Amazon personal data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 or an equivalent standard. Credentials and tokens are stored encrypted and are never logged in plain text.
Access control. Access follows the principle of least privilege. Only personnel who need access to provide the service have it, access is individually assigned, logged and reviewed, and it is revoked when it is no longer needed.
Incident response. We maintain an incident response plan. In the event of a security incident affecting Amazon personal data, we investigate, contain and remediate, and we notify Amazon within 24 hours of becoming aware, alongside our obligations towards you and towards the Autoriteit Persoonsgegevens.
Subprocessors. Any subprocessor that handles Amazon personal data is bound by equivalent obligations in writing.
Comparable obligations imposed by bol, eBay, Kaufland and other connected channels apply in the same way to data originating from those channels.
For personal data originating from Amazon, we comply with the Amazon Data Protection Policy and the Amazon Acceptable Use Policy. This means in particular:
Purpose limitation. Amazon personal data is used solely to fulfil orders placed through Amazon and to provide the service to you as the seller of record. It is not used for marketing, not enriched with data from other sources, not resold, and not shared with any party other than those needed to fulfil the order.
Retention and deletion. Amazon personal data is retained for no longer than 30 days after order delivery, after which it is permanently deleted, except where retention is required by law. Where retention is legally required, the data is archived in encrypted form, access is restricted to the personnel who need it for that legal purpose, and it is deleted once the legal retention period expires.
Encryption. Amazon personal data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 or an equivalent standard. Credentials and tokens are stored encrypted and are never logged in plain text.
Access control. Access follows the principle of least privilege. Only personnel who need access to provide the service have it, access is individually assigned, logged and reviewed, and it is revoked when it is no longer needed.
Incident response. We maintain an incident response plan. In the event of a security incident affecting Amazon personal data, we investigate, contain and remediate, and we notify Amazon within 24 hours of becoming aware, alongside our obligations towards you and towards the Autoriteit Persoonsgegevens.
Subprocessors. Any subprocessor that handles Amazon personal data is bound by equivalent obligations in writing.
Comparable obligations imposed by bol, eBay, Kaufland and other connected channels apply in the same way to data originating from those channels.
12. Automated processing
Our demand forecasting analyses your own order and stock history to predict future demand. This analysis runs on your own account data and is not used to make decisions about individuals. We do not carry out automated decision-making with legal or similarly significant effects on individuals.
13. Changes to this policy
We may update this policy for operational, legal or regulatory reasons. Material changes are announced on our website or by email.
Last updated: 16-09-2026







