Privacy policy
How we handle personal data. Last updated 17 August 2026.
The short version
We hold two very different sets of people's data, and it matters which is which. Account holders are the people who sign in to Nilstock — we are the data controller for them. Store users are the employees whose names and badge numbers your organisation loads into the system so it can record who took what. For those people you are the controller and we are your processor: we hold their data on your instructions and do nothing else with it.
Data we hold about account holders
- Name, work email address, and a hash of your password — never the password itself.
- Your company name, sites, and the role you have been given.
- Sign-in records: time, IP address and browser, kept so that you and we can see if someone else has been in your account.
- Billing details, held by Stripe. We never see or store a card number.
Lawful basis: performance of a contract for the account itself, and legitimate interests for the security records.
Data you load about your staff
Typically a name, a staff number, a department, sometimes a work email address, and a badge or card identifier. Then every movement they make: what they took, when, at which site, and against which work order or cost centre.
This is employee monitoring data and should be treated as such. Your staff should know the system exists and what it records — in most cases that means telling them, and in some it means a data protection impact assessment. We can help with the technical detail; the decision is yours because you are the controller.
We do not use it to train anything, we do not sell it, and we do not look at it except when you ask us to help with a support problem.
Where it lives
On servers in the United Kingdom and the European Union. Our hosting provider is Railway and the database is PostgreSQL. Backups are encrypted and held in the same region.
Who else processes it
- Railway — hosting and database.
- Stripe — payments. Card details go to Stripe directly and never touch our servers.
- Resend — transactional email: invitations, overdue reminders, low-stock digests.
That is the complete list. If it changes we will update this page and, for material changes, tell customers before it takes effect.
How long we keep it
For as long as your account is open. The movement ledger is append-only by design — it is the audit trail the product exists to provide — so individual entries are not edited or deleted, and corrections are recorded as new entries.
When someone leaves your organisation you archive them rather than deleting them, which keeps historical movements attributable. If you need a person erased entirely, ask us: we will discuss what that means for the integrity of your audit trail before doing it, because the two aims genuinely conflict and you should choose knowingly.
If you close your account, we delete your data within 30 days. Export everything first — CSV export is always available, including while an account is read-only for non-payment.
Cookies
Only ones that make the product work: a session cookie when you sign in, an optional long-lived cookie if you tick "trust this computer", and a token that identifies a paired terminal. All are strictly necessary, so there is no consent banner because there is nothing to consent to. We run no advertising or cross-site tracking cookies.
Your rights
Under UK GDPR you may ask for a copy of your data, correction of it, erasure, restriction, or portability, and you may object to processing. Write to [email protected] and we will respond within one month.
If you are one of the staff whose movements are recorded, please ask your employer first — they control that data and we are obliged to refer you to them. We will help them respond.
You may also complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first, but it is your right either way.
Security
Passwords are hashed with Argon2id. Session, device and terminal tokens are stored only as hashes. Every row in the database is scoped to a company and that scoping is enforced in one central place rather than trusted to each page. See security for the detail.
Changes
We will post changes here and update the date at the top. For anything that materially affects how we handle your data, we will email account owners before it takes effect.