Privacy Policy
Last updated: August 14, 2026
This Privacy Policy explains how StockSteer (operated by Vidgenix Limited, "StockSteer", "we", "us") collects, uses, and protects information when you visit our website, request a free allocation diagnosis, or use the StockSteer service. StockSteer is a business-to-business service; it is designed for use with business sales data, not personal data.
1. Who is responsible for your data
Vidgenix Limited, registered at Unit 1406B, 14/F, The Belgian Bank Building, Nos. 721–725 Nathan Road, Mong Kok, Kowloon, Hong Kong, is the data controller for the information described in this policy. You can reach us at liu_ky@hisuntech.com for anything privacy-related.
2. What we collect
Information you give us
- Contact details — your work email address and, optionally, your name and store or company name, when you request a diagnosis or write to us.
- Sales data files — the CSV or report files you upload or email to us for a diagnosis. These should contain business sales records only: SKUs, order dates, quantities, prices, inventory levels, and similar operational data.
Information we ask you NOT to give us
We ask you to remove customer personal data (buyer names, addresses, emails, phone numbers) from files before sending them. We do not want or need this data. If personal data is nevertheless included in a file you send, we will delete those fields or the file as soon as we identify it, and we will not use it for any purpose.
Information collected automatically
Our website does not use advertising or cross-site tracking cookies. Our hosting provider may collect standard server logs (IP address, browser type, pages visited) for security and operations. Our pages load fonts from Google Fonts, which means Google receives your IP address when the page loads; no cookies are set by this. If we later add privacy-respecting analytics, we will update this policy first.
Platform data (when you connect your stores)
The StockSteer product connects to Shopify and to Amazon via the Amazon Selling Partner API (SP-API) using each platform's official authorization flow and read-only permissions, and reads order, inventory, and product data. We request only the minimum roles needed for inventory analysis; we do not request Amazon's restricted (PII) roles or Restricted Data Tokens, and we exclude buyer personal data wherever the platform allows. Section 8 describes how Amazon data is handled in detail.
3. How we use it
- To produce and deliver your allocation diagnosis and discuss it with you.
- To operate, secure, and improve our website and service.
- To contact you about your diagnosis, the StockSteer product, and early access — you can opt out of non-essential email at any time.
- To comply with legal obligations.
We do not sell your data. We do not use your sales data to train machine-learning models, build benchmarks, or produce aggregated products without your explicit consent. Your file is used to produce your diagnosis, nothing else.
4. Legal bases (GDPR / UK GDPR)
Where these laws apply, we process your data on the basis of: contract (producing the diagnosis you requested), consent (marketing email, any optional processing), and legitimate interests (site security, service improvement) balanced against your rights.
5. Who we share it with
Only service providers that help us run StockSteer — hosting and storage, email delivery, and form handling — each bound by data-processing agreements to protections equivalent to this policy, and each assessed for third-party risk before use. A current list of subprocessors is available on request at liu_ky@hisuntech.com. We may also disclose information if required by law, or as part of a merger or acquisition (in which case this policy continues to apply to data collected under it). We never share your sales data with other merchants, advertisers, or data brokers.
6. How long we keep it
- Sales data files: kept while we prepare your diagnosis and for the follow-up conversation, then deleted within 90 days of your last interaction with us — or immediately on request.
- Contact details: kept until you ask us to delete them or unsubscribe.
- Server logs: retained by our providers on standard short rotation.
7. Security
Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256) with our storage providers, with keys handled through a managed key-management system. Access follows least privilege with multi-factor authentication and account lockout after repeated failed logins, is revoked promptly when no longer needed, and is logged; security logs are retained for at least 12 months and monitored for anomalies. Backups are encrypted and geographically separated from primary storage. We run a vulnerability-management program that targets resolution of critical findings within 7 days and high-risk findings within 30 days of discovery. No method of transmission or storage is perfectly secure, but we treat your sales data as the commercially sensitive information it is.
8. Amazon Selling Partner API data
When you connect an Amazon account, StockSteer accesses Amazon data as an SP-API solution provider, and we handle that data in accordance with Amazon's Data Protection Policy and Acceptable Use Policy in addition to this Privacy Policy:
- Authorization and scope. Access happens only after you authorize StockSteer through Amazon's official OAuth flow, is read-only, and is limited to the least-privilege roles needed for inventory analysis (orders, inventory, listings). We do not request restricted (PII) roles or Restricted Data Tokens, and we do not receive Amazon buyer personal data. You can revoke access at any time in Seller Central.
- Purpose limitation. Amazon data is used solely to provide the inventory-analysis services you authorized. It is never used for advertising, never sold or rented, never disclosed except to the subprocessors in Section 5, and never aggregated across sellers or used to build benchmarks or train models without your explicit consent.
- Retention and deletion. We keep Amazon data only as long as needed to provide the service, and in no case longer than 18 months, unless a longer period is required by law. If you disconnect your Amazon account or close your StockSteer account, or if Amazon requires deletion, we permanently delete Amazon-sourced data within 30 days. Any buyer personal data received despite our configuration is deleted as soon as it is identified, and in all cases within 30 days.
- Security controls. The measures in Section 7 (TLS 1.2+, AES-256 at rest with managed keys, least-privilege access, account lockout, 12-month log retention, vulnerability-resolution SLAs, geographically separated backups) apply to all Amazon data we hold.
- Incident response. We maintain a documented incident-response plan with a designated Incident Management Point of Contact. If we detect a security incident affecting Amazon data, we notify Amazon through its designated security-incident channel within 24 hours, and affected sellers without undue delay.
- Subprocessors and audits. Subprocessors that touch Amazon data are bound by written agreements to protections equivalent to ours and undergo third-party risk assessment. We cooperate with audits and verification requests from Amazon and its affiliates or representatives as required by the Data Protection Policy.
9. Your rights
Depending on where you live (including under GDPR, UK GDPR, and the CCPA/CPRA), you may have the right to access, correct, delete, or receive a copy of your data, to restrict or object to processing, and to withdraw consent. Email liu_ky@hisuntech.com and we will respond within 30 days. You also have the right to complain to your local data-protection authority. We do not discriminate against you for exercising any of these rights.
10. International transfers
Our providers may process data in countries other than yours, including the United States. Where required, transfers are protected by recognized safeguards such as Standard Contractual Clauses or adequacy decisions.
11. Children
StockSteer is a business service and is not directed at anyone under 16. We do not knowingly collect data from children.
12. Changes to this policy
If we change this policy materially, we will update the date above and, where we have your email, tell you directly before the change takes effect.
13. Contact
Vidgenix Limited · Unit 1406B, 14/F, The Belgian Bank Building, Nos. 721–725 Nathan Road, Mong Kok, Kowloon, Hong Kong · liu_ky@hisuntech.com