Stockd ← Back to Stockd

Privacy Policy

Mintd Ltd
Last updated: September 2026

1. Who We Are

This Privacy Policy applies to Mintd Ltd ("Mintd", "we", "us", "our"), a company registered in England and Wales under company number 16677272, with our registered office at 82A James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE.

Stockd (available at stockd.uk) is the company brain for businesses that move physical things. It is sold as two products:

Stockd reads from the systems a business already runs. It does not replace that business's accounting system.

We are registered with the Information Commissioner's Office (ICO) as a data controller. ICO data controller registration: ZC132944 (Mintd Ltd, registered 24 April 2026). This registration covers both Mintd and Stockd.

For any privacy-related enquiries, please contact us at: hello@stockd.uk

2. Our Commitment to Your Privacy

We are committed to protecting your personal data and handling it responsibly, transparently, and in compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and all other applicable data protection legislation. Where we process data relating to individuals outside the United Kingdom, we comply with applicable international data protection laws including the EU General Data Protection Regulation (EU GDPR) where relevant.

3. Who This Policy Applies To

This policy applies to:

Stockd and all Mintd products are intended exclusively for business use by individuals aged 18 and over. We do not knowingly collect or process personal data of individuals under the age of 18.

4. What Personal Data We Collect

4.1 Data you provide directly

Account and business registration data:

Consultation requests:

Where you submit the consultation form on stockd.uk, we collect your full name, business name, work email address, optional phone number, and the answers you give about the systems your business currently runs.

Contact records entered by our customers:

Stock and operational records (Stockd Records):

Product descriptions, photographs, quantities, locations, batch and date information, valuations, purchase orders, sales orders, goods in and despatch records, stock counts, barcode scans, and the documents attached to any of those records. Where a record identifies the member of staff who made, moved, counted or approved something, that name forms part of the record.

Data read by Stockd Intelligence:

Where a customer enables Stockd Intelligence, we process data drawn from the systems that customer connects to it. This may include accounting ledger data, stock and warehouse system data, the contents of shared folders the customer nominates, and scanned or photographed paperwork including handwritten forms. Personal data may appear anywhere within that material. Connections to a customer's own systems are read-only: Stockd does not write back into a customer's accounting or warehouse system.

{{ NEEDS LEGAL REVIEW: Stockd Intelligence ingests an open-ended body of customer material, including shared folders and scanned paperwork, in which personal data of the customer's staff, suppliers and contacts may appear incidentally and without our being able to enumerate it in advance. A solicitor needs to settle how this is described, what the controller and processor split is for incidentally ingested personal data, whether a DPIA is required before Intelligence takes its first paying customer, and what the customer must warrant about the material it connects. }}

Payment information:

Payment card and bank details for Stockd fees are collected and processed directly by our third-party payment processor. We do not store, transmit, or have access to your full payment card details at any time.

{{ NEEDS LEGAL REVIEW: This policy previously described the collection of government-issued identity documents (passport and driving licence scans) uploaded for anti-money laundering purposes under the Money Laundering Regulations 2017, together with the associated special safeguards in section 5.5 and the five-year retention period in section 7. That processing belonged to the previous dealer-facing product. A decision is needed on whether Stockd collects identity documents at all under the current product, and if it does not, sections 5.5 and the identity-document retention rule must be removed rather than merely reworded. }}

4.2 Data we collect automatically

Technical and usage data:

Cookies and similar technologies:

Please see Section 10 (Cookies) for further information.

5. How We Use Your Personal Data

We process your personal data on the following lawful bases under UK GDPR:

5.1 Performance of a contract (Article 6(1)(b))

We use your data to:

5.2 Legal obligation (Article 6(1)(c))

We process certain data to comply with our legal obligations, including:

5.3 Legitimate interests (Article 6(1)(f))

We process certain data where it is in our legitimate business interests to do so, provided those interests are not overridden by your rights:

{{ NEEDS LEGAL REVIEW: Neither this policy nor our Terms of Service currently states a lawful basis for the automated processing carried out by Stockd Intelligence, which reads a customer's ledger, shared folders and paperwork, sends extracted content to a third-party large language model provider, and generates findings and proposed actions from it. A solicitor needs to settle the lawful basis for that processing, whether a legitimate interests assessment is required and in what terms, and how it interacts with the customer's own role as controller of the underlying material. }}

5.4 Consent (Article 6(1)(a))

Where we rely on your consent:

You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before withdrawal.

5.5 Automated processing and human approval

Stockd prepares work and proposes actions. It does not take actions on a customer's behalf without a person approving them. Where an agent within Stockd drafts a purchase order, assembles a pack of evidence, or proposes a correction to a record, a named user must approve it before it has any effect, and the approval is recorded against that person in the audit trail. Stockd does not write into a customer's accounting or warehouse system.

{{ NEEDS LEGAL REVIEW: The paragraph above is a description of how the system is built. It needs review against Article 22 UK GDPR and against the automated decision-making right asserted in section 12 of this policy, to confirm that the human approval gate is sufficient to keep this outside solely automated decision-making, and to settle what must be disclosed about the logic involved. }}

{{ NEEDS LEGAL REVIEW: This section previously covered the processing of passports and driving licences uploaded for anti-money laundering purposes, on the basis of legal obligation. It has been replaced because that processing belonged to the previous dealer-facing product. If Stockd does still receive identity documents in any circumstance, this section must be restored and redrafted rather than removed. }}

6. Data Processed on Behalf of Our Customers

When a customer uses Stockd to store and manage personal data about their own suppliers, customers and staff, and when a customer connects their ledger, stock system, shared folders or paperwork to Stockd Intelligence, Mintd acts as a data processor on behalf of that customer, who is the data controller for that data.

Customers are responsible for:

Mintd processes this data solely in accordance with the customer's instructions and does not use it for any independent purpose.

If you are an individual whose personal data has been entered into Stockd by one of our customers and you wish to exercise your data subject rights, you should contact that business directly in the first instance. If you are unable to do so, you may contact us at hello@stockd.uk and we will assist in directing your request appropriately.

{{ NEEDS LEGAL REVIEW: This section asserts a processor relationship but there is no data processing agreement in place, and none is referenced here or in the Terms of Service. Article 28 UK GDPR requires a written contract containing specified terms between controller and processor. A DPA needs to be drafted and either incorporated into the Terms of Service or offered as a separate document, and this section must then point at it. It must cover the sub-processors listed in section 8, including the large language model provider used by Stockd Intelligence, and the customer's right to object to changes of sub-processor. }}

7. Data Retention

We retain your personal data for as long as is necessary for the purposes set out in this policy, or as required by law.

Active accounts: We retain all account and workspace data for the duration of your agreement with us.

After your agreement ends: Following the end of your agreement, we retain your data for a period of 30 days to allow you to export your records or reinstate your account. After this period, your workspace data is permanently deleted from our systems.

{{ NEEDS LEGAL REVIEW: The retention periods in this section were written against a monthly subscription that no longer exists, and against a product that no longer exists. Retention needs to be re-decided for: the audit trail and approval records, which are designed to be append-only and are not deleted in the ordinary course; ingested source documents and page images held in object storage; extracted text chunks and the vector embeddings derived from them; and the nightly per-tenant export archives. Each needs a stated period and a stated basis. }}

{{ NEEDS LEGAL REVIEW: This section previously stated a five-year retention period for identity documents held under the Money Laundering Regulations 2017, and an indefinite retention right over "asset and ownership records", meaning timestamped ownership chain entries and item provenance records. The second of those describes Mintd Passport, not Stockd, and should not appear in Stockd's privacy policy at all. Both need to be removed or replaced by a solicitor rather than by us. }}

Financial and billing records: We retain financial transaction records for a minimum of six years in accordance with HMRC requirements.

Backup copies: Encrypted backup copies of data may be retained for up to 90 days after deletion from the live system before being permanently purged.

8. Sharing Your Personal Data

We do not sell your personal data to third parties. We do not share your personal data with third parties for their own marketing purposes.

We share personal data only in the following circumstances:

{{ NEEDS LEGAL REVIEW: This section names categories of sub-processor but not the sub-processors themselves, and a business customer evaluating Stockd Intelligence will ask specifically where its data goes. As at September 2026 the platform runs on Vercel (application hosting and serverless functions), Supabase (Postgres database and object storage, hosted in the eu-west-1 region), Anthropic (the large language model used by Stockd Intelligence), a commercial optical character recognition API with a self-hosted Tesseract fallback, Resend (email), Twilio (SMS) and Stripe (payments). A decision is needed on whether to publish a named sub-processor list here or in a separate document, how customers are notified of changes to it, and what right they have to object. The OCR vendor is not fixed in the architecture document and must be named before any list is published. }}

{{ NEEDS LEGAL REVIEW: We make no statement anywhere about whether customer data is used to train any model. The system architecture records a standing engineering policy of no fine-tuning, with retrieval and structure applied over a general model, and the model provider is currently Anthropic. Whether that engineering policy is turned into a binding customer-facing commitment, and in what words, is a commercial and legal decision. It is the first question a competent buyer will ask, and it must be answered here and in the Terms of Service before Stockd Intelligence has a paying customer. }}

9. International Data Transfers

Some of our third-party service providers are based outside the United Kingdom and the European Economic Area. Where we transfer personal data to countries that do not provide an equivalent level of data protection to the UK, we ensure appropriate safeguards are in place, including:

You may request further information about the safeguards in place for international transfers by contacting us at hello@stockd.uk.

{{ NEEDS LEGAL REVIEW: This section needs to be made specific. Our primary database and object storage are hosted in the eu-west-1 region, which is in Ireland and therefore outside the United Kingdom, and material sent to the large language model provider used by Stockd Intelligence may be processed outside both the UK and the EEA. A solicitor needs to confirm which transfer mechanism applies to each, whether the UK International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses is the correct instrument, and whether a transfer risk assessment is required. }}

10. Cookies

We use cookies and similar tracking technologies on our websites and platform.

Essential cookies: These are strictly necessary for the platform to function. They include authentication session cookies that keep you logged in. You cannot opt out of essential cookies without affecting platform functionality.

Marketing and analytics cookies: With your consent, we may use cookies to understand how our website and platform are used and to deliver relevant marketing. You can manage your cookie preferences at any time through our cookie consent tool.

{{ NEEDS LEGAL REVIEW: This section says we use marketing and analytics cookies with consent, but the cookie banner on stockd.uk tells visitors that Stockd uses essential cookies only and does not use tracking or advertising cookies. The two statements contradict each other and one of them is wrong. Whichever is correct, the other must change. }}

{{ NEEDS LEGAL REVIEW: This section refers the reader to a Cookie Policy "available on our website". No such page exists and nothing links to one. Either the policy must be written and published, or this reference must be removed. }}

11. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

No method of transmission over the internet or method of electronic storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where required.

12. Your Rights

Under UK GDPR you have the following rights in relation to your personal data:

To exercise any of these rights, please contact us at hello@stockd.uk. We will respond to your request within one calendar month. We may need to verify your identity before processing your request.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with applicable law. The ICO can be contacted at ico.org.uk or by calling 0303 123 1113.

13. Children

Our products and services are intended exclusively for business use by individuals aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@stockd.uk and we will take steps to delete it promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes we will notify active users by email or by displaying a prominent notice within the platform. The date at the top of this policy indicates when it was last updated.

We encourage you to review this policy periodically.

{{ NEEDS LEGAL REVIEW: This policy was re-dated to September 2026 as a whole, because the description of the products, the description of the customer and the categories of data processed have all changed. Confirm that re-dating the whole document is the right approach, and whether existing customers need to be notified of the change under this section. }}

15. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please contact us:

Mintd Ltd
82A James Carter Road
Mildenhall
Bury St Edmunds
IP28 7DE
Email: hello@stockd.uk
ICO Registration: ZC132944 (registered 24 April 2026; covers Mintd and Stockd)

This Privacy Policy was prepared in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It should not be taken as legal advice. Mintd Ltd recommends that this policy is reviewed by a qualified solicitor before being published.