Stackt App Privacy Policy

Last updated: 17 August 2026

The Stackt App ("we," "our," or "us") is the customer mobile application of Stackt Ltd, a moving and storage company. The App lets you view and manage your storage account: see the items you have in storage, book the return of your items, review your orders and storage plan, and contact our support team. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App"). Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the App.

1.1 Information You Provide to Us

We collect information that you provide directly to us when you use the App, including:

  • Phone Number: The App uses your mobile phone number as your account identifier. To sign in, you enter your phone number and confirm it with a one-time code sent to you by SMS. There is no password and no in-app registration — your account is created when you become a Stackt customer

  • Delivery Details: When you book the return of your stored items, you provide a delivery address (entered via an address search), floor number, lift and parking availability, and a preferred delivery date and time slot

  • Return Requests: The selection of items you would like returned from storage

  • Support Communications: Information you choose to share when contacting our support team by phone, email, or WhatsApp. These conversations happen in your own phone, email, or WhatsApp apps, not inside the App

1.2 Information Automatically Collected

When you use the App, we may automatically collect certain information, including:

  • Device Information: Device manufacturer and model, operating system and version, platform, and device language. We do not collect advertising identifiers, device serial numbers, or your precise location

  • Usage Data: Which screens you visit and which features you use (for example, viewing your items or booking a return), collected through our analytics service (Amplitude) and linked to your customer ID — never to your name, phone number, or email. See Section 5.3 for details

  • Authentication Tokens: Session tokens that keep you signed in to the App

  • Error Monitoring (Sentry and Firebase Crashlytics): When errors or crashes occur, we collect crash reports, stack traces, device and OS information, and app version. For sessions that end in an error, a fully masked replay of screen activity may be recorded (all text and images are obscured). Personal data such as phone numbers, emails, names, and addresses is filtered out of error reports before they leave your device. See Section 5.2 for details

1.3 Information from Our Service Records

The App displays information we already hold about you as a Stackt customer, retrieved securely from our servers:

  • Account Profile: Your name, phone number, and email address from our customer records

  • Storage Inventory: A list of your items in storage, including item names, categories, quantities, and photos of your items taken by our warehouse team when they were placed into storage

  • Order Information: Your order history, order statuses, dates, and prices

  • Storage Plan: Your current plan, storage size, and weekly price

1.4 Information from Third-Party Services

We may receive information from third-party services that we use:

  • Firebase Authentication: Confirmation of your phone number verification and authentication tokens

We use the information we collect to:

  • Sign You In Securely: Verify your phone number by SMS code and maintain your session

  • Show Your Account: Display your storage inventory, item photos, orders, and plan

  • Process Return Bookings: Arrange the delivery of your items to the address you provide. After you book a return, our Customer Success Team will contact you using the contact details on your account to confirm the date and details

  • Improve the App: Analyze usage patterns, identify issues, and enhance user experience

  • Communicate with You: Respond to your inquiries and provide customer support

  • Ensure Security: Protect against fraud, unauthorized access, and other security threats

  • Comply with Legal Obligations: Meet legal requirements and respond to legal requests

If you choose to book a new collection from the App, the App opens our website checkout in your browser. The link contains no personal data — you enter your details on the website, which is governed by our website Privacy Policy.

3.1 Data Storage

Your data is stored on:

  • Our Backend Servers: Your account profile, storage inventory, orders, and booking information are stored on our secure servers at api.stackt.app; photos of your stored items are served from our content delivery servers at cdn.stackt.app

  • Firebase Services: Phone number verification data and authentication tokens are processed by Firebase (Google) servers

  • Local Device Storage: The App keeps your pair of session tokens in secure system storage (iOS Keychain / Android Keystore-backed encrypted storage), excluded from cloud backups and device-to-device transfers. Your profile, inventory, and orders are not saved to your device; photos you view may be temporarily cached by the App on your device, and our analytics and error-monitoring services store a pseudonymous customer ID and a random app-generated identifier locally

3.2 Security Measures

We implement appropriate technical and organizational security measures to protect your information, including:

  • Encryption of all data in transit using HTTPS/TLS

  • Phone number verification via SMS one-time codes (Firebase Authentication)

  • Short-lived access tokens with rotating refresh tokens, held in secure device storage

  • Automatic filtering that removes personal data (phone numbers, emails, names, addresses, postcodes) from analytics and error reports before they are sent

  • Server-side access controls so you can only ever see your own account's data

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.

We do not sell your personal information. We may share your information only in the following circumstances:

  • Service Providers: We may share data with third-party service providers who perform services on our behalf, including:

    • Firebase (Google) for phone number authentication

    • Sentry for error monitoring

    • Amplitude for product analytics

    • HubSpot, our customer relationship management system, where your customer records are held

    • Cloud storage and hosting providers

  • Legal Requirements: We may disclose information if required by law, court order, or government regulation

  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred

  • With Your Consent: We may share information with your explicit consent

The App uses the following third-party services that may collect information:

5.1 Firebase (Google)

  • Purpose: Phone number verification at sign-in (sending the SMS one-time code) and native crash reporting (Firebase Crashlytics)

  • Data Collected: The phone number you enter at sign-in, authentication tokens, and crash diagnostics. During verification, Google may use device integrity checks (Google Play Integrity on Android, silent push or reCAPTCHA on iOS) to confirm the request comes from a genuine device

  • Privacy Policy: https://firebase.google.com/support/privacy

5.2 Sentry

We use Sentry to monitor app stability, diagnose crashes, and improve performance. Sentry may collect and process the following data on our behalf:

  • Purpose: Error and crash monitoring, performance monitoring, and replay of sessions in which an error occurred, to help us reproduce and fix issues

  • Data collected: Error events and stack traces; device type, OS version, and app version; and technical logs. Reports are linked to your internal customer ID only — we do not send your name, phone number, email, or IP address to Sentry, and personal data is automatically filtered out of reports before sending. Session replays are recorded only for sessions where an error occurs and are fully masked: all text, images, and screen content are obscured

  • Data processing: Data is sent to Sentry's servers in the United States and is processed in accordance with our instructions and Sentry's privacy policy

  • Privacy Policy: https://sentry.io/privacy/

5.3 Amplitude

We use Amplitude to understand how the App is used so we can improve it. Amplitude may collect and process the following data on our behalf:

  • Purpose: Product analytics — which screens are visited and which features are used

  • Data collected: Usage events (for example, viewing your items or booking a return), session information, platform, OS name and version, device manufacturer and model, device language, and app version. Events are linked to your internal customer ID with your market and storage plan as the only profile attributes — your name, phone number, and email are never sent to Amplitude. We have disabled the collection of advertising and hardware device identifiers (advertising ID, IDFV, App Set ID), carrier, country, and IP address by the Amplitude SDK; Amplitude instead identifies your device by a random app-generated identifier, which is reset when you sign out

  • Data processing: Data is sent to Amplitude's servers in the United States and is processed in accordance with our instructions and Amplitude's privacy policy

  • Privacy Policy: https://amplitude.com/privacy

The App does not request access to your camera, photo library, location, contacts, microphone, or notifications. It requires only an internet connection.

The photos of your stored items shown in the App are taken by our warehouse team and displayed from our servers — the App never accesses your device's camera or photo library, and it does not track your location. The App does not use your device's identifiers for advertising and does not track you across other apps or websites.

We retain your information for as long as necessary to:

  • Provide the App and our storage services to you

  • Comply with legal obligations

  • Resolve disputes and enforce agreements

  • Maintain business records as required by law

Your sign-in session on a device remains valid for up to 180 days of inactivity. Signing out immediately removes the session tokens and your account data from that device; images you have viewed may remain in the App's cache until the system clears it. We recommend signing out before selling or disposing of a device, or before uninstalling the App, as secure system storage may otherwise retain session data.

You can delete your Stackt account from within the App at any time: Account → Delete Account. Deleting your account takes effect immediately and cannot be undone — you will not be able to sign in again, and every signed-in session on every device is ended straight away. We then delete or anonymise your personal information, except for the limited records we are required by law to keep, as described above.

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request access to your personal information

  • Correction: Request correction of inaccurate information. Your profile details, including your phone number, can be updated by contacting our support team

  • Deletion: You can delete your account yourself in the App at any time — Account → Delete Account. This ends your access immediately; we then delete or anonymise your personal information except where we are legally required to keep it (see Data Retention). You can also ask us to delete your personal information by emailing [email protected]

  • Portability: Request a copy of your data in a portable format

  • Opt-Out: Opt out of certain data collection and processing activities

  • Withdraw Consent: Withdraw consent for data processing where applicable

To exercise these rights, please contact us using the contact information provided below. You do not need to contact us to delete your account — you can do that yourself in the App at any time.

The App is not intended for use by children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

We operate in the United Kingdom and the United Arab Emirates. Your information may be transferred to and processed in countries other than your country of residence — in particular, our analytics and error monitoring providers (Amplitude, Sentry) and Firebase (Google) process data in the United States. These countries may have different data protection laws. By using the App, you consent to the transfer of your information to these countries.

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected

  • Right to delete personal information

  • Right to opt-out of the sale of personal information (we do not sell personal information)

  • Right to non-discrimination for exercising your privacy rights

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page

  • Updating the "Last Updated" date

  • Notifying you through the App (for significant changes)

Your continued use of the App after changes constitutes acceptance of the updated Privacy Policy.

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Email: [email protected]

Phone: +44 20 4634 3751

Website: https://www.stackt.co.uk/

Address: 411 Oxford Street, Office 1.01 W1C 2PE London, United Kingdom

Company Name: Stackt Ltd

Data Controller: Stackt Ltd

Contact: [email protected]

By using the Stackt App, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.