Your stocktake file is your P&L in miniature. Wet sales by line, your GP%, every loss you've had this year, what you paid for every product. In a tied pub that's the raw material of a rent conversation. So before you type it into anybody's cloud, including mine, it's worth twenty minutes on three questions: who owns it, who can see it, and how you get it back out.

Almost nobody asks. The buyer's checklist covers price and features; this is the data chapter it deserves.

Whose data is it

UK GDPR has two roles worth knowing. The controller decides what data is collected and why. The processor handles it on the controller's instructions. When you put your venue into stocktaking software, you're the controller and the vendor is your processor. In plain terms: the numbers are yours, and the vendor works for you, not the other way round.

Strictly, most of a stocktake is business data rather than personal data, and UK GDPR bites hardest on the personal kind. But the roles still describe the deal correctly, and the vendor's obligations to you, security, confidentiality, doing only what they're instructed to do, are the things you're checking when you ask the questions below. The ICO's data security guidance is the plain-English baseline for what good handling looks like.

The pubco question

This is the one tied tenants actually care about, so let's take it straight. There are two different documents in your life. The stock audit your pub company commissions is theirs: they paid for it, their auditor produced it, and you should assume they hold every number in it. The audit guide covers living with that.

The numbers in software you pay for yourself are a different thing. Access should be invitation-based: your team sees your venue because you added them, and nobody else does. Ask any vendor plainly: can anyone outside my team see venue-level numbers, ever? StockTap's answer is no. You invite people, you set their role, you remove them, and there is no side door for a pub company, a brewery or a stocktaker you didn't add.

One honest caveat, and it isn't legal advice: your tenancy or lease may oblige you to share certain figures or accept audits. Software doesn't change what your agreement says. What it changes is that your own working numbers live somewhere that answers to you.

Where the data lives

Ask which country the servers are in. Under UK data protection rules, data held in the UK is straightforward and the EEA is covered by an adequacy decision, so EU hosting is the boring, compliant kind of answer. Anywhere else and the vendor should be able to name the safeguard they rely on. The ICO's international transfers guide is the short version. StockTap's data is hosted in the EU, in Frankfurt. If a vendor can't or won't tell you where your numbers physically live, that's your answer about how they think about the question.

Staff accounts are the actual personal data

The stock itself is mostly business data. The moment you invite your team, though, you're holding names, emails and activity of real people, and that part is squarely personal data with you as controller. The hygiene is not complicated, and the ICO's small business guidance keeps it proportionate:

  • No shared logins. One person, one account, so the count history means something and a leaver can be removed without changing everyone's password.
  • Remove leavers the week they leave, same as the till code and the door code.
  • Roles matched to the job. The person doing Tuesday's count doesn't need the finance screen.

This is also, quietly, a stock control feature: an account per person is what makes a count, a wastage entry or a delivery signature attributable when a variance question comes up later, without anyone having to rely on memory. The adoption guide covers who actually needs an account at all.

The exit is the test

The single most revealing data question is the leaving one. UK GDPR gives individuals a right to data portability in a machine-readable format; for your business records the practical equivalent is blunter: can you, yourself, today, export everything without asking permission or phoning anyone?

If the answer is a CSV button you can press on a Tuesday night, you're fine. If exporting your own numbers requires a conversation with the sales team, you have learned something important before paying anything. The switching guide is built on this: export first, then decide, and keep a current export in your own files regardless, because the practical protection against a vendor disappearing is a recent copy, not a clause.

Six questions for any vendor

AskA good answer sounds like
Where is my data hosted?A country, named without hesitation. UK or EEA keeps it simple.
Who can see my venue's numbers?Only accounts you invite. No partner, group or supplier access you didn't create.
Can I export everything myself, today?Yes, CSV from the app, no phone call.
What happens when I cancel?A stated retention period and deletion on request, in writing.
Is my data aggregated, shared or sold?A clear answer in the privacy policy, not a shrug.
How do staff accounts work?Individual logins with roles, and you can remove people yourself.

For StockTap the answers I can give you flat out: hosted in the EU, invite-only teams with roles you control, and CSV export from the reports whenever you want it. The rest is written down in the privacy policy, which is linked in the footer of every page, where it should be.

Common questions

Is stocktake data personal data under UK GDPR?

Mostly no. Sales figures, stock counts and GP% are business records. Your staff accounts are personal data though, names, emails and activity, and for those you're the controller with the usual duties: keep them secure, keep them accurate, remove them when there's no reason to hold them.

Can my pub company see my stocktaking software?

Not unless you invite them. The audit your pubco commissions is their document and you should assume they keep every number in it, but software you pay for yourself should be invitation-only at venue level, and you should ask the vendor to confirm that plainly. Whether your agreement obliges you to share particular figures is a lease question, so read it; software doesn't change what you signed.

What happens to my data if the software company goes bust?

Practically, the protection is a recent export in your own files, not anything in the terms. Export a full CSV after every count or at least monthly. If the vendor vanished tomorrow you'd lose the tool, which is replaceable, and keep the history, which isn't.

Is cloud software safe enough for a pub?

Done properly, it's usually safer than the alternative most pubs actually run, which is a spreadsheet on one laptop, emailed about with no backup. A serious vendor patches, backs up and encrypts better than any of us do on our own. Your end of the deal is the boring part: real passwords, no shared logins, leavers removed. The ICO's security guidance covers the rest.

Sources