Skip to main content
StockTaker Software
StockTaker Software

Privacy Policy

Effective October 2026


This policy covers the StockTaker Android app and the StockTaker service at api.stocktakersoftware.com. Both are provided by StockTaker Software ("we").


StockTaker is business software for hospital materials management. It is licensed to healthcare organizations, which run it on handheld scanners for their staff. If you use StockTaker at work, your organization decides how the app is set up on your device. It can also answer questions about how your organization uses the counts you make.


What the app sends us

The app talks to a single server, api.stocktakersoftware.com, and only over an encrypted (HTTPS) connection. It sends:


• Your organization's license key. It identifies the organization and facilities the device works for.

• A device identifier. This is Android's per-app device ID (ANDROID_ID), which tells one scanner from another.

• The device's make, model and Android version. Also the app version.

• The device name that your organization gives the scanner in StockTaker's settings, such as "Scanner" or "ER1".

• The operator's initials, if the operator enters them. Initials are optional. The app sends them until the next count is submitted, then clears them from the device.

• Settings for the upload file name: the date format, and whether the stock list's name goes into the file name.


Counts

When an operator taps SUBMIT, the app uploads the count. This is the item numbers and the quantities counted, the stock lists they belong to, and what the routine asks for:


• a department number for a Department Issue or Return;

• the supplying inventory for a Restock Requisition;

• the patient ID or account number for a Patient Issue, which charges supplies to a patient's account.


The server writes each count as a file in the organization's own StockTaker ownCloud folder. The organization then loads it into its materials management system. The file name is made from the device name, the operator's initials (if entered), the stock list, the facility and the date and time.


Diagnostics

The app also sends diagnostic events. They tell us when the app crashed or froze, when an upload failed and whether the scanner started, along with how long downloads and start-up took and how the device is configured. The app also sends a summary of each count session: how many items were scanned or typed, how long the session took and which features were used. These summaries contain counts and on/off flags only. They never contain item numbers, quantities, initials, patient IDs or the device name.


A crash report includes the program's technical stack trace. The app removes the license key from every diagnostic event before sending it.


An organization can switch diagnostics off for all its devices through its device-management (MDM) system. The setting is remoteLoggingEnabled. When it is off, the app sends no diagnostic events. Counts and the information above are still sent, because the app cannot work without them.


What the app does not collect

The app does not ask for or collect your location, contacts, photos, camera, microphone or phone number. It has no user accounts and no advertising. It contains no third-party analytics or advertising code. Versions 3.41.0 and earlier also load a font from Google Fonts when the Help screen is opened, which shows Google the device’s IP address; later versions make no such request.


What our server records

For every request, our server logs the time, the address it came from (IP address), the device identifier, device name, model, Android version and app version, and the outcome. It does not log the license key itself.


We also keep a register of the devices that use each license: when we first and last saw each one, and the app version it runs. We use it to support your organization's devices and to see which versions are in use.


How we use it

We use this information only to:


• provide the service: check the license, deliver the stock lists and deliver the counts to your organization;

• support your organization's devices;

• find and fix faults;

• understand which features are used.


We do not sell it, and we do not use it for advertising.


Who we share it with

We do not share this information with third parties. The service runs on Amazon Web Services in the United States (us-east-1), which hosts it for us. Counts are made available only to the organization that made them, in its own StockTaker ownCloud folder.


How long we keep it

• Request and diagnostic logs: 90 days, then deleted automatically. The web server's own access log, which records each request's address and app version, is kept for 30 days.

• Count files: in your organization's ownCloud folder until your organization deletes them. Our backups keep a deleted file for up to 90 more days.

• The device register and the usage summaries: until your organization asks us to delete them.


Your choices and deletion requests

There are no user accounts in StockTaker. The data it handles belongs to the organization that licenses it.


To ask what we hold about your organization's devices or your initials, or to have it deleted, email info@stocktakersoftware.com. Include the organization's name and, if you can, the device names concerned. We answer within 30 days. Your organization can delete count files from its ownCloud folder at any time.


Security

All traffic between the app and our server is encrypted with TLS. The license key is kept in the app's private storage on the device. Access to the server and to your organization's files is limited to StockTaker Software staff who need it to run the service.


Children

StockTaker is a workplace tool for adults. It is not directed at children.


Changes

If this policy changes, we will post the new version here with a new effective date.


Contact

StockTaker Software · info@stocktakersoftware.com · stocktakersoftware.com