Privacy Policy

Effective date: September 27, 2026 · Last updated: September 27, 2026

This Privacy Policy explains how Stonepath Brands LLC, doing business as Stack For Wellness ("we", "us"), handles data in the Stack For Wellness internal operations platform at app.stackforwellness.com (the "Service"). This policy covers the Service only. Purchases on our storefronts are covered by the storefront privacy policy.

Who uses the Service

The Service is an internal tool. Only Stonepath Brands LLC and its owner use it, and it connects only to Google Accounts owned or operated by Stonepath Brands LLC or its owner. It does not accept outside users.

Google user data we access

With the account owner's consent through Google's OAuth consent screen, the Service accesses the following Google user data:

How we use Google user data

We use Google user data only to provide the features described on our home page: email triage, supplier correspondence, supplier and product records, store content checks, and operator alerts. We do not use it for any other purpose.

AI processing

The Service is run by AI models. Google user data that the Service reads, such as the text of an email or document, is sent to third-party AI model providers so the model can complete the requested task, such as sorting, summarizing, or drafting a reply. These providers process the content only to complete that task. Under their terms, they do not use it to train their models, and they keep it only briefly, if at all, for security and abuse monitoring. We do not use Google user data to train, retrain, or fine-tune any AI or machine learning model.

Operator notifications

The Service reports results to the business owner through business messaging services (Slack and Telegram). These messages can include excerpts of Google user data, such as an email summary or a draft reply for review.

Google API Services — Limited Use Disclosure

Stack For Wellness's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Google user data:

Storage and retention

The Service runs on infrastructure operated by Stonepath Brands LLC in the United States. OAuth credentials are stored in files that only the operator's system account can read. Email, documents, and other Google user data remain in the connected Google Account. Working copies made while completing a task, such as message excerpts in logs or task history, are kept only as long as needed for business operations and records, and are deleted on request.

When access is revoked, the Service stops accessing the account and we delete the stored credentials for it.

Sharing

We never sell Google user data. We share it only with service providers that are needed to run the Service's features, such as the AI model providers and the messaging services (Slack and Telegram) described above, or when the law requires it.

How to revoke access

The owner of a connected Google Account can remove the Service's access at any time at myaccount.google.com/permissions. After access is revoked, the Service can no longer access that account's data.

Changes to this policy

If we change this policy, we will update the "Last updated" date at the top of this page.

Contact

Questions about this policy: joel@stackforwellness.com.