Last updated: 27 August 2026
This notice explains how WimStock handles personal data. It applies to the WimStock iOS and
Android apps, the web app at <your-company>.wimstock.com, and this website.
WimStock is a stock-control tool sold to trades businesses that run vans. Most of the data in it is about stock, not people — but recording who scanned what, and where, necessarily involves some personal data. We keep that to what the job needs.
This determines who you should approach about your data.
For the people who sign up for and administer a WimStock account, and for visitors to this website, including waitlist, contact-form and stock-leak calculator enquiries.
For everything inside a customer's workspace — the stock records, movements, photos and staff accounts belonging to a business using WimStock. That business is the controller. We process it only on their instructions, to provide the service.
If you use WimStock because your employer asked you to, your employer decides what is recorded about you and for how long. Ask them first about access or deletion — we'll help them respond, but we can't act on their data without their instruction.
Your name, work email address, role (admin, manager or installer), the van you're assigned to, and which business you belong to. Sign-in is passwordless — we send a one-time link or a short code, and store a session identifier in a secure cookie. We never store passwords.
Legal basis: performance of a contract.
What was scanned in, out, moved, fitted or adjusted: the product, quantity, location, van, job reference, any notes you type, and who did it and when. This is the audit trail your employer is paying for.
Legal basis: performance of a contract.
An approximate position captured only at the moment you record stock as fitted or used on a job, together with an accuracy figure. It is not continuous, there is no background tracking, and no route or journey history is kept. It exists so the business can see where stock was consumed and match it to the right job.
You can decline, and the app keeps working — the movement is simply recorded without a position. If you've granted it and change your mind, turn it off in your device settings at any time.
Legal basis: your consent, given through your device's location permission.
Photos you take of products, boxes and installations, using the camera or chosen from your photo library. Product photos are sent to Anthropic to identify the item automatically.
Legal basis: performance of a contract.
We log basic request metadata — URL, response status, timing, IP address, app version — to keep the service running and to spot abuse. This is first-party operational logging, not advertising tracking.
Legal basis: our legitimate interest in keeping the service reliable and secure.
Business contact and subscription details. Direct Debit mandates are set up and held by GoCardless — we never see or store your bank details.
Legal basis: performance of a contract, and our legal obligation to keep accounting records.
Whatever you type into the waitlist, contact or stock-leak calculator forms — typically name, email and company.
Legal basis: our legitimate interest in replying to you; consent for any marketing email, which you can withdraw at any time using the unsubscribe link.
We don't collect special category data, we don't use advertising or cross-site trackers, and we don't sell personal data to anyone.
We may also disclose data where the law requires it, or to protect our rights or someone's safety. If the business is ever sold or transferred, data may pass to the buyer under the same protections.
Your data is stored on Cloudflare's network. Some processors — Anthropic and Resend among them — may process data outside the UK, including in the United States, under the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
Under the UK GDPR you have the right to:
Email loading… and we'll respond within 30 days. As explained above, if the data sits inside your employer's workspace we'll pass the request to them.
All traffic is encrypted in transit. There are no passwords to steal — sign-in is by one-time link or short-lived code. Session cookies are HttpOnly, Secure and SameSite, so scripts can't read them. Every database query is scoped to a single business, so one customer's workspace can't reach another's. Credentials for connected services are encrypted at rest. If a breach affects your rights, we'll tell you and the ICO as the law requires.
We use only what the service needs to work: a session cookie once you sign in, and short-lived sign-in tokens. No advertising or cross-site tracking cookies, so there's no consent banner to click through.
WimStock is a workplace tool sold to businesses and isn't aimed at children. If we learn we hold data about a child, we'll delete it.
If we materially change this notice we'll update the date at the top and, where it significantly affects you, tell account administrators by email.