Privacy Policy
Last updated 5 September 2026
RestockGenie keeps a shared list of what your team has in stock and what needs ordering. This policy explains what we hold to do that, who else sees it, and what you can ask us to do with it.
Who we are
RestockGenie is operated by Ruthwik Kadavakolanu and John Huang. There is no company between us and you: we run it personally, and we are the controllers of the account data described below. For the inventory data your organization puts into the service, your organization is the controller and we process it on their behalf.
What we collect
When you create an account: your email address, your first and last name, and the name of your organization. If you set a password we store a bcrypt hash of it, never the password itself.
When you sign in with Google or Apple: the provider's name, the account identifier they give us, and the email address on that account. We do not receive or store a profile picture.
As you use the service: the items, quantities, storage locations and sites you record; restock requests and order history, each carrying the name of the person who raised it and when; and two display preferences, your avatar colour and whether you prefer the light or dark theme.
Automatically: your IP address, used to rate-limit requests and recorded in server logs. Standard request metadata — the URL, the response status, how long it took — is logged alongside it.
What we do not collect
This list is as much a part of the policy as the one above.
- No camera images. Scanning happens entirely on your device and runs only while the Scanner page is open. No photo or video is uploaded, and none reaches our servers.
- No analytics or tracking. There is no analytics provider, no advertising network, no tracking pixel and no third-party script anywhere in the product.
- No selling or sharing. We do not sell personal information and we do not share it for advertising.
- No card numbers on our servers. Stripe collects payment details on its hosted checkout. RestockGenie stores billing identifiers, subscription status, invoice information, and payment history. The current sandbox uses test payment details.
Why we process it
To run the service you asked for: authenticating you, keeping your organization's inventory, and sending the transactional email the account needs — verification codes, sign-in links and password resets. We also process it to keep the service secure and available, which is what the rate limiting and logging are for. There is no other purpose; nothing here is used for profiling or marketing.
Who else processes it
These are the only third parties involved, and what each one handles:
- Google — sends all transactional email over Gmail SMTP. Also handles sign-in, and reads your spreadsheet, if you choose to use Google sign-in or the Google Sheets importer.
- Apple — handles sign-in, only if you choose to use it.
- Stripe — handles subscription checkout, payment methods, invoices, and the billing portal when an owner chooses a subscription.
- Render — hosts the application and its database, and holds the server logs described above.
Cookies
We set cookies to keep you signed in and to protect forms against cross-site request forgery. They are signed, and they exist to make the service work. There are no advertising or analytics cookies, which is why you are not being asked to consent to any.
How long we keep it
Account and inventory data is kept for as long as the account is open, because it is the thing the service exists to remember. Short-lived credentials — verification codes, sign-in links, password reset tokens — expire on their own and are cleared automatically. Server logs are kept for as long as our hosting provider retains them.
Your rights
You can ask us for a copy of your data, to correct it, or to delete it. Depending on where you live you may also have the right to object to or restrict processing, and to complain to a data protection authority.
How to exercise them: write to restockgenie@gmail.com. There is no self-serve delete button in the product yet, so deletion is handled as a request rather than a click — we would rather say that plainly than point you at a control that does not exist. Disconnecting a Google or Apple account from your profile does already remove the identity record we hold for it.
Security
Passwords are hashed with bcrypt on a dedicated worker pool. Sessions are signed. Requests are rate-limited per client. Access to an organization's data is controlled by membership and role, and every request is checked against it. We do not hold any security certification, and we would rather say so than imply one.
International transfers
Our hosting and email providers may process data outside your country. Where that happens we rely on the safeguards those providers offer.
Children
RestockGenie is a workplace tool. It is not directed at children and we do not knowingly collect their data.
Changes to this policy
If we change it, we will update the date at the top. If a change materially affects how we handle your data, we will tell account owners by email rather than relying on you to notice.
Contact
Questions or requests: restockgenie@gmail.com. This policy is governed by the laws of the State of California.