Privacy Policy
Last updated: August 4, 2026
This policy covers the platform itself. Two roles matter: for merchants (people who build stores here) we are the data controller of your account. For shoppers (people who buy from a store built here) the merchant is the controller of your customer data — we process it on the merchant’s behalf to run their store. Each store also publishes its own policies.
What we collect
- Merchant accounts: your email and a securely hashed password, plus everything you add to your store (products, pages, images, settings).
- Shopper data (on behalf of merchants): order details, email, shipping address, optional account profile, saved addresses, wishlists, and reviews for the store you shopped at.
- Payment data: card details go directly to Stripe — they never touch our servers. We store only payment references (order totals, Stripe identifiers).
- Analytics: storefront traffic is measured with cookie-less, aggregate daily counters (page views, visits). No advertising trackers, no cross-site tracking, no profile of you is built.
Cookies
We use essential cookies only: a session cookie to keep merchants and shoppers signed in, and a cart cookie so a shopper’s cart survives page loads. There are no third-party advertising or analytics cookies. If a store enables a web-font preset, fonts load from Google Fonts or Fontshare CDNs (a standard network request, no cookie set by us).
Who processes data for us
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and content delivery.
- Stripe — payment processing and merchant payouts.
We do not sell personal data, and we do not share it with anyone beyond these processors except where the law requires.
Retention
Merchant and store data is kept while the account is active. Order records are retained by merchants for accounting and legal obligations even if a shopper account is deleted; personal details are removed or anonymized on request as described below.
Your rights
- Shoppers: if the store offers accounts, you can view your data, export a copy, and delete your account from the store’s account page. You can also contact the merchant directly — they control your customer relationship.
- Merchants: you can export your catalog and customer data from the dashboard (CSV), and closing your account removes your store. Contact us for anything the dashboard doesn’t cover.
- Depending on where you live (e.g. under the GDPR), you may also have rights to correction, restriction, portability, and to lodge a complaint with a supervisory authority.
Security
Every store’s data is isolated with database row-level security; public storefront reads go through restricted interfaces rather than direct table access, and passwords are hashed by our authentication provider. No system is perfectly secure, but isolation between stores is the design’s first rule.
Changes
We may update this policy as the product evolves; material changes will be announced in the dashboard or by email, with the date above updated.
Contact
Questions? Contact the platform operator via the address published on this platform’s website.