Privacy Policy

Effective September 11, 2026

Who operates this service

Stok MCP is maintained by Abdulaziz Abdurashidov for Stok operations. Questions can be sent through the support page.

Information handled

When an authorized user connects, the service handles their Stok account identifier, name, phone number, roles, and advertiser profile for authentication and access control. At the user's request it reads owner-scoped advertising statistics or role-approved warehouse, inventory, seller-contact, worker-activity, order, hub, courier, waybill, return, and operational-finance records. Customer names, customer phone numbers, and exact street addresses are intentionally excluded from tool output.

Why it is used

Information is used only to authenticate users, answer the operational question they requested, keep the service secure, and troubleshoot availability. Stok MCP does not sell personal information or use it for advertising or model training.

Sharing and processors

Tool results are returned to the MCP client chosen by the user, such as ChatGPT. OpenAI or another selected client processes that content under its own terms and privacy policy. The service also relies on its hosting provider and the Stok Laravel authentication API strictly to operate authentication and delivery.

Storage and retention

The application does not maintain a separate database of prompts or tool results. OAuth credentials are signed or encrypted and expire automatically. Infrastructure security logs may temporarily contain IP address, request time, path, and status, and are retained only as needed for security and operations, normally no longer than 30 days.

Controls

Users may disconnect Stok MCP in their client. Stok administrators can revoke source-account permissions. Requests to access, correct, or delete applicable personal information can be made through support. Some operational records must remain in the source system under Stok's legal or business retention duties.

Security and changes

Access uses OAuth, role checks, encrypted transport, bounded read-only tools, and a database account restricted to a read-only replica. Material policy changes will be published on this page with a new effective date.