🔒 Privacy & Data Security Standard

Privacy Policy

Last Updated: August 2026 • Official Privacy Policy for StockGrid Android

1 Overview & Scope

StockGrid ("we", "our", or "us", operated by SRC93-tech) provides a multi-device inventory operating platform designed specifically for garments, apparel, and textile businesses. This Privacy Policy explains how our mobile application and related cloud services collect, protect, and handle your business data.

We adhere to a strict principle of data minimization: we only process data essential to synchronizing your inventory, securing staff access, and providing accurate reporting across your authorized devices.

2 Information We Collect

To operate the StockGrid inventory system, the following data categories are processed:

  • Firm & Account Details: Firm name, administrator email address, currency format (e.g., INR ₹), and localized timezone settings.
  • Inventory Catalog & Transaction Data: Article codes, item descriptions, garment & apparel size matrices (e.g., S, M, L, XL, XXL / Waist 28–44), categories, minimum stock thresholds, wholesale/retail pricing, and timestamped stock in/out audit records.
  • Product Photos: Article reference images captured or uploaded by your team, stored in isolated, encrypted cloud storage buckets.
  • Device Registry Identifiers: Device hardware model, operating system version, and unique installation tokens used to enforce multi-device authorization and allow remote device revocation.

Isolated Tenant Storage

Every firm's database records are strictly segmented using PostgreSQL Row Level Security (RLS). No other firm or external organization can view or access your inventory items.

3 Device Permissions & Usage

The StockGrid mobile application requests specific device permissions strictly for functional inventory operations:

📷 Camera Permission

Used exclusively when you activate the live Barcode/QR Scanner or capture a photo for an inventory item. We never access the camera in the background or store continuous camera feeds.

💾 Secure Storage & App Preferences

Used to securely store authenticated session tokens in platform hardware keychains (via Flutter Secure Storage / Android Keystore) and manage user interface preferences.

🔔 Push Notifications (Optional)

Used to deliver inventory alerts (such as restock shortage thresholds) and device authorization verification notices.

4 Data Security & Real-Time Sync

We implement enterprise-grade security protocols across all communication channels and backend databases:

  • Encryption in Transit: All data exchanged between your devices and our Supabase cloud database is encrypted via TLS 1.3 with HTTPS/WSS protocols.
  • Encryption at Rest: Database records, authentication tokens, and uploaded media files are encrypted at rest using AES-256 standards.
  • Automated Cloud Backups: Daily automated cloud database backups and on-demand administrator Google Drive archives safeguard your firm's records.

5 Staff Mode & Admin PIN Protection

StockGrid includes role-based access control to protect sensitive financial metrics within your warehouse:

When operating in Staff Mode, sensitive metrics such as wholesale buy prices and total warehouse inventory valuations are obscured. Full access requires entering the firm's 4-digit Master PIN, which is verified securely and never transmitted in plaintext.

6 Third-Party Services & Google Drive Backups

We do not sell, rent, monetize, or trade your inventory, customer, or transaction data with any third-party advertisers or data brokers under any circumstances.

Optional Google Drive Cloud Backups

When the administrator initiates a manual or scheduled Google Drive backup, an encrypted archive of your inventory catalog and audit history is uploaded directly to your own authorized Google Drive account via official Google OAuth APIs. StockGrid does not access, monetize, or store your Google account credentials.

7 Data Retention & Deletion Rights

You maintain complete ownership and control over your inventory records:

  • Device Reset: You can instantly revoke and erase cached credentials from any device using the in-app "Sign Out & Reset This Device" feature.
  • Remote De-Authorization: Administrators can remove lost or decommissioned employee phones from the Device Management console.
  • Permanent Account Deletion: You may request complete, permanent deletion of your firm's database records and uploaded media at any time by contacting our support team.

8 Contact Us

If you have any questions, data requests, or security inquiries regarding this Privacy Policy, please reach out to us:

StockGrid Data Protection Office

Email: src93.appsupport@gmail.com

Platform: StockGrid for Android (SRC93-tech)