Legal

Privacy Policy

What personal information Stoaken collects, why, who processes it for us, and the choices and rights you have.

Last updated 7 October 2026

In short

  • We collect what we need to run Stoaken: your name and email, what you and your team put in, and the basics of how the service is used.
  • We don’t sell personal information, don’t show ads, don’t use analytics cookies and don’t train AI models on your content.
  • A small set of providers run parts of the service for us: hosting, the database, sign-in, email and payments.
  • You can delete your account yourself in Settings, Account, and ask us about anything else at the address below.

1.Who we are

Stoaken (“we”) runs Stoaken and is responsible for your personal information under this policy (the “responsible party” under South Africa’s POPIA, or “controller” under the GDPR). For anything about your personal information, including reaching our Information Officer, email privacy@stoaken.com.

When a workspace adds people and content, that workspace’s owner decides what goes in. We process it on their behalf to provide the service.

2.What we collect

  • Account details: your name and email address, and an identifier from our sign-in provider. We never see your password.
  • What you put in: tokens, themes, components, comments, releases and approvals, with who did what and when. That record is the point of the product.
  • People you invite: their email address and the role you choose for them.
  • Outside reviewers on share links: the name and email they give, and their comments.
  • Billing: whether a workspace pays, its plan, seat count, billing period and our payment provider’s customer reference. Card and bank details go to Paddle, never to us.
  • Technical information: request counts per API key (for rate limits), webhook delivery results, security logs and the server logs our hosting provider keeps.
  • Connections you choose to make: for example a Penpot access token, which we store encrypted.

Cookies: one cookie keeps you signed in. Your light or dark display choice is saved in your own browser. We don’t use advertising or analytics cookies, so there’s nothing to opt out of.

3.How we use it

  • to provide Stoaken: sign you in, show your workspaces, resolve and export tokens, run previews and visual checks;
  • to send the emails the product sends, such as invitations, review requests and comment notifications (you can mute threads);
  • to keep the service and your data secure, prevent abuse and enforce rate and plan limits;
  • to bill paying workspaces and answer support questions;
  • to meet legal obligations.

Our legal basis is providing the service you signed up for, our legitimate interest in keeping it secure and working, and legal obligations. We don’t sell personal information, don’t use it for advertising, and don’t use your content to train AI models.

4.Who we share it with

People in your workspace see your name, email and activity on shared content, and people you share a link with see what that link shows. Beyond that, these providers process personal information for us, under contracts that limit them to doing so:

  • Supabase: our database and file storage;
  • Vercel: hosting for the app and the API;
  • WorkOS: sign-in;
  • Resend: sending email;
  • Paddle: payments, as our reseller and merchant of record. Paddle’s own privacy notice covers the payment details you give it.

Penpot receives requests only if you connect it. We may disclose information when the law requires it, and we’ll tell you if we can.

5.Where it’s processed

Our providers may process information outside South Africa, including in the European Union and the United States. We rely on their contractual and legal safeguards for those transfers.

6.How long we keep it

We keep your account details while your account exists. When you delete your account, your name, email and sign-in identity are removed and your API keys are revoked. The workspace’s records stay, so its history still makes sense, but they point to an anonymous reference instead of you.

Content belongs to its workspace and stays until the workspace removes it. Backups held by our database provider roll off on its schedule. Billing records are kept as long as tax law requires.

7.Your rights

You can ask to see, correct or delete your personal information, object to how we use it, or ask us to stop. You can delete your own account at any time in Settings, Account. For anything else, email us and we’ll reply within 30 days.

If you’re unhappy with how we handle your information, you can complain to the Information Regulator in South Africa, or to the data protection authority where you live.

8.Security

Information travels encrypted. Who sees what is enforced in the database itself, for every request. API keys are stored only as hashes, and connection tokens and webhook secrets are encrypted. No system is perfectly secure; if something goes wrong that affects you, we’ll tell you and the regulator as the law requires.

9.Children

Stoaken is for work and isn’t meant for anyone under 18.

10.Changes to this policy

If we change this policy in a way that matters, we’ll tell you by email or in the app before it takes effect.

11.Contact

Questions or requests: privacy@stoaken.com.