Privacy Policy

Last updated: September 26, 2026 · Version 1.0 · Questions: legal@restock.supply

This Privacy Policy explains how Restock, Inc. ("Restock", "we", "us", "our"), collects, uses, shares, and protects personal information in connection with the Restock platform — a multi-tenant software-as-a-service application for beverage distribution, including route accounting, payments, contract management, distributor and territory management, and a brand marketplace (collectively, the "Service").

Restock is a business-to-business product. Our direct customers are businesses (beverage suppliers and distributors), and the individuals who use the Service are typically their employees and authorized representatives. This policy applies to personal information we process about visitors to our websites, individuals who create accounts, and individuals whose information is contained in data our customers upload — to the extent we act as a controller of that information.

Contents 1. Who we are 2. Information we collect 3. How and why we use information 3.1 Artificial intelligence and automated processing 4. Controller and processor roles 5. Sharing and sub-processors 6. International transfers 7. Data retention 8. Security 9. Your rights (GDPR / UK GDPR) 10. Your rights (California — CCPA/CPRA) 11. Children and minors 12. Cookies and similar technologies 13. How to exercise your rights 14. Changes to this policy 15. Contact us

1. Who we are

Restock, Inc. is the entity responsible for the Service. For account and website data described below, Restock is the data controller. For business data that our customers upload and process through the Service, our customers are the controllers and Restock acts as a processor on their behalf (see Section 4). You can reach our privacy team at privacy@restock.supply.

2. Information we collect

2.1 Account and contact data

When you register for or are invited to a workspace, we collect identifiers and contact details such as your name, business email address, phone number, job title, employer/organization, profile photo (if provided), and authentication credentials (password hashes, multi-factor settings). For customer administrators and billing contacts, we also collect billing names and addresses.

2.2 Business data our customers upload

Customers use the Service to manage their distribution operations. This may include data about their stores, accounts, routes, sales representatives, products and catalogs, orders, returns, invoices, contracts, supplier and distributor relationships, territories, and uploaded documents. Where this data contains personal information (for example, the name and contact details of a store buyer, route driver, or supplier contact), Restock processes it on the customer's instructions as a processor.

2.3 Usage and telemetry data

We automatically collect technical information when you use the Service, including IP address, device and browser type, operating system, pages and features accessed, timestamps, referring URLs, and diagnostic logs. We use this to operate, secure, troubleshoot, and improve the Service.

2.4 Cookies and local storage

We use a small set of cookies and browser local storage to keep you signed in, remember your selected workspace, and track onboarding progress. See our Cookie Policy and Section 12.

Browser storage does more than that in Restock. The product is local-first: a substantial amount of working data is written to the browser on the device you are using rather than to our servers. That includes records you create in parts of the product that have no server-side store at all (routes, drop-offs, key-account contacts, reports and team lists), the proof-of-service visit records described in Section 2.7, and the proof-of-delivery images described in Section 2.8 while they are waiting to upload. Contracts and invoices are a mixed case: the browser always holds the working copy, and whether a copy also reaches our database depends on which screen created the record — the contract builder and the invoice screens write to the browser only. Data held only in your browser is under your control and outside ours: clearing site data deletes it permanently, and we cannot read it, export it, or delete it on your behalf. Section 7 says which categories this applies to.

2.5 Payment metadata

Subscription and payment processing is handled by Stripe, Inc. We receive and store payment metadata such as the last four digits of a card, card brand, expiration month/year, billing postal code, transaction identifiers, and invoice records. Restock does not collect or store full payment card numbers. Stripe processes full card details directly under its own privacy terms.

2.6 Communications

If you contact support, request documents, or correspond with us, we keep records of those communications, including the content of your messages.

Some workspaces use an intake address to receive reports and purchase orders by email. Where that is configured, we store the sender address, subject, message body, and any attachments that arrive at it, including messages from people who are not Restock users and who did not choose to send anything to us — a supplier or distributor emailing a report to their trading partner. Mail from a sender the workspace has not approved is stored and held for an administrator to review rather than processed.

2.7 Location data

The driver application collects precise device location. When a driver grants their browser's location permission, we receive a continuous stream of position fixes — latitude, longitude, accuracy, speed, and heading — for as long as that screen stays open. We use these fixes to draw the driver's own position on their map, to detect arrival at a stop automatically (a 100-metre radius around the stop plus a 60-second stationary test), and to stamp each stop event with the distance from the store, whether the driver was on site (recorded as on site when the fix is within 200 metres of the store), and the accuracy of the fix.

Position updates are not only shown to the driver. Each update, together with the driver's identifier and first name, is broadcast live to other authorized users of the same workspace — in practice a dispatcher or manager watching a fleet map. The derived stop record is kept afterwards as proof that a visit happened. Section 7 covers how long each of these lasts.

Location is collected only after the driver's browser or device grants permission, and that permission can be withdrawn at any time in browser or device settings. Withdrawing it stops live tracking and automatic check-in; stops can still be recorded by hand. Because these fixes describe an identifiable employee during working hours, they are data about the customer's own personnel: the employing customer is the controller and Restock is the processor, as set out in Section 4.

Route optimization and turn-by-turn directions are produced by a third-party routing service. The coordinates being routed — the driver's current position and the coordinates of the stops on the route — are sent to that service. See Section 5.

Field reps. When a rep starts a visit and when they complete it, and their company records location on visits (the default, which a company can turn off), we store the position the phone reports at those two moments, with its accuracy and the time, against that visit. We also store where and when each visit photo was taken. We use these to show the rep's manager where the visit happened and to check that it happened at the store. Nothing is recorded between visits. The phone asks for permission first, and the rep can withdraw it in the phone's settings at any time; visits can still be logged without it.

Separately, the site can be put behind a private-beta access gate. It is switched off in the current build. While it is on, unlocking it asks the visitor's browser for location before any account exists; a coordinate returned that way is rounded to three decimal places (roughly 100 metres) and recorded with the browser's user agent, time zone, and language in the access log. Declining is remembered on that device and we do not ask again.

2.8 Proof-of-delivery photographs and signatures

At a delivery stop, a driver can take a photograph with the device camera and can capture a handwritten signature drawn on screen. Both are stored as images, with a label and a timestamp, against the stop they belong to. A signature image is captured from the person who signs for the delivery.

A photograph taken inside a store shows whatever is in front of the camera, which can include staff, customers, or passers-by who are not Restock users and who have given us nothing themselves. Customers instruct us to store these images and are responsible under the Terms for having the rights and consents needed to capture them; we ask that drivers photograph the delivery rather than the people around it.

These images are written to browser storage on the capturing device and are also uploaded to our file storage so they survive that device. Until an upload is confirmed, the device holds the only copy. Retention is described in Section 7.

3. How and why we use information

We process personal information for the purposes below. Where the EU or UK General Data Protection Regulation ("GDPR") applies, the legal basis for each purpose is identified.

3.1 Artificial intelligence and automated processing

Two features of the Service use a third-party artificial-intelligence provider. Both are optional, and neither runs unless you use the feature.

Training. We do not send Customer Data to any AI provider for the purpose of training or fine-tuning models, and we use these services under commercial terms rather than consumer terms. Anthropic is listed as a sub-processor in our Trust Center, and is covered by the sub-processor commitments in our DPA.

No decisions with legal or similarly significant effects. These features classify documents and order stops. They do not make decisions about a person that produce legal effects or similarly significantly affect them, and no automated decision-making of that kind is performed by the Service.

Accuracy. Extraction output is a suggestion. It is presented for review and is not applied to your records without a person confirming it.

If you would prefer that this processing not occur in your workspace, contact privacy@restock.supply and we will disable the feature for your account.

4. Controller and processor roles

Restock plays two distinct roles depending on the data in question:

5. Sharing and sub-processors

We do not sell personal information. We share personal information only as described here:

6. International transfers

Restock is based in the United States, and our sub-processors may process data in the United States and other countries. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary measures where required. You may request a copy of the relevant transfer mechanism by contacting privacy@restock.supply.

7. Data retention

We retain account and contact data for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. Billing and tax records are retained for the periods required by applicable law. Usage logs are retained for a limited period for security and troubleshooting. Business data we process as a processor is retained per our customer's instructions and the DPA; on termination we delete or return it as described there.

Three categories need saying separately, because their retention is not the same as the rest:

More generally, any data described in Section 2.4 as living only in your browser is retained until you clear it. It is not part of any backup we hold and it is not reachable by a deletion request made to us; you delete it by clearing site data on that device.

8. Security

We maintain technical and organizational measures designed to protect personal information, including encryption in transit and at rest, tenant isolation, access controls, and monitoring. Learn more in our Security Overview. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights (GDPR / UK GDPR)

If you are in the EEA, the UK, or Switzerland, you have the following rights with respect to personal information for which Restock is the controller, subject to conditions and exceptions in applicable law:

You also have the right to lodge a complaint with your local data protection authority. We would, however, appreciate the chance to address your concerns first.

10. Your rights (California — CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, provides the following rights with respect to personal information for which Restock is a business:

California "Shine the Light" (Cal. Civ. Code § 1798.83): Because we do not share personal information with third parties for their direct marketing purposes, no "Shine the Light" disclosure is required; you may nonetheless contact us with related requests at privacy@restock.supply.

You may submit a request through an authorized agent; we will require reasonable verification of identity and authority.

11. Children and minors

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16 years of age, consistent with the California Age-Appropriate Design Code Act ("Cal-AGE") principles. If you believe a minor has provided us personal information, please contact us at privacy@restock.supply and we will take appropriate steps to delete it.

12. Cookies and similar technologies

We use strictly necessary and functional cookies and browser local storage, and we record which pages of the Service a signed-in user opens, in our own database, to understand how the product is used. We do not use a third-party analytics product and we do not use advertising cookies. Browser storage is also where a large part of your working data lives — see Section 2.4. For details, see our Cookie Policy.

13. How to exercise your rights

To exercise any right described above, email privacy@restock.supply with the nature of your request. We will verify your identity before acting and respond within the timeframes required by applicable law (generally within 30 days under GDPR and 45 days under CCPA/CPRA, with extensions where permitted). If you do not receive an acknowledgement from us, please also submit the form at restock.supply/contact, which tells you on screen whether your message was actually delivered. If your information sits within a customer's workspace where Restock is a processor, we will route your request to that customer (the controller) and assist them.

Two practical limits are worth stating plainly:

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update constitutes acceptance of the revised policy.

15. Contact us

Restock, Inc.
Privacy: privacy@restock.supply
Legal: legal@restock.supply
Security: security@restock.supply

EU / UK Representative: [Placeholder — Restock will appoint an Article 27 GDPR / UK representative prior to launch where required. Contact details to be inserted here.]