1. Who we are
StockRescue AI is an inventory intelligence and decision-support service operated by [Legal entity name to be confirmed], [Registered business address to be confirmed]. References to "we", "us" and "our" mean the operator of the service. References to "you" and "customer" mean the business that holds a StockRescue AI account and the users acting on its behalf.
2. Account and company information we collect
When an account is created we collect the information needed to authenticate users and separate one business from another:
- Account identity: email address and, if provided, full name.
- Authentication data: a securely hashed password managed by our authentication provider, plus session and sign-in metadata (timestamps, sign-in method).
- Company profile: company name, industry, reporting currency and locale preference.
- Workspace membership and role (for example owner, admin, analyst) used to control what each user may see or change.
- Subscription and plan status associated with the workspace.
- Basic technical logs such as request timestamps, error events and coarse usage counters used to keep the service reliable and to control abuse.
3. Inventory and sales data uploaded by customers
The core of the service is inventory data that a customer chooses to upload, typically as a CSV file. This can include product identifiers (SKU), product and category names, quantity on hand, unit cost and price, currency, purchase or received dates, last sale dates and sales quantities over a period.
We treat uploaded inventory data as customer data. It is processed on the customer's behalf and only for the purposes described in this policy. Customers should not upload personal data about consumers, employees or other individuals — StockRescue AI does not require it and the file format is not designed for it.
4. How inventory data is used
Uploaded data is used to:
- Validate the file and report rows that are inconsistent or cannot be imported.
- Compute deterministic risk metrics — inventory age, sales velocity, time since last sale and stock coverage — and derive per-product risk scores and an overall inventory health score.
- Aggregate results into dashboard metrics such as high-risk inventory value, dead-stock value and category concentration.
- Generate rule-based recommendations (for example discount, bundle, liquidate, stop reordering) from those calculated figures.
- Optionally produce a plain-language explanation of a calculation when a user explicitly requests it.
5. Third-party infrastructure and AI providers
We rely on third-party providers to operate the service: a managed cloud database and authentication platform, application hosting, and a large-language-model provider used only for written explanations. Providers act as processors on our behalf under their respective agreements.
All financial figures, risk scores and recommendations are calculated by our own deterministic engine. The AI layer never computes, changes or invents numbers; it only describes figures that were already calculated.
When a user requests an explanation, we send a minimized, structured summary of the relevant records — for example SKU, category, quantity, value, age in days, velocity and the calculated score — together with the question asked. Volume is capped, and the request is limited in size and rate.
We do not send passwords, password hashes, session tokens, API keys, database credentials or provider secrets to any AI provider. AI requests are not used by us to train models.
6. Tenant isolation
StockRescue AI is multi-tenant. Every stored record carries the identifier of the company that owns it, and database row-level security policies restrict every read and write to the company of the signed-in user. Role changes and company creation are performed only through server-side routines that derive the company from the authenticated session, never from values supplied by the browser.
The same company scope is applied before any data is summarized for an AI explanation, so an explanation can only ever describe the requesting company's own inventory.
8. Data retention and deletion
Our retention principles are:
- Customer data is retained while the workspace is active, so that historical uploads and trends remain available.
- Uploads, products, analysis results and recommendations can be replaced by a new upload or deleted by an authorized user of the workspace.
- On verified request from a workspace owner we will delete the workspace and its inventory data.
- Operational logs and aggregated, non-identifying counters may be kept for a limited period for security, billing and reliability purposes.
- Backups held by our infrastructure providers expire on their own schedule after deletion.
9. Security
Access to the service requires authentication. Data is transmitted over encrypted connections and stored by our infrastructure provider with encryption at rest. Privileged database routines are restricted, role assignment is server-controlled, and AI requests are rate-limited and size-limited. No system is perfectly secure; customers are responsible for protecting their own credentials.
10. Your choices and requests
To request access to, correction of, export of, or deletion of your data, or to ask a question about this policy, contact [Privacy contact email to be configured]. We will confirm that the request comes from an authorized user of the workspace before acting on it. Applicable statutory rights depend on the customer's jurisdiction and will be described in the final version of this policy.
11. Changes to this policy
This policy may be updated as the product develops or as legal requirements change. The date at the top of the page reflects the current version, and material changes will be communicated to workspace owners.
12. Draft status
This document is a pre-launch draft. Items shown in square brackets — including [Legal entity name to be confirmed], [Registered business address to be confirmed] and [Privacy contact email to be configured] — must be completed and the whole document reviewed by qualified legal counsel before commercial launch.