This Data Collection Policy is the itemized companion to our Privacy Policy. Where the Privacy Policy explains our principles, this document lists precisely what we gather, where it comes from, why we process it, the lawful basis for each purpose, and how long we retain it. Our guiding rule is data minimization: we collect only what a feature genuinely needs, and no more.
At a glance
Overview
This policy itemizes the data Storek collects across the marketing website, the merchant dashboard, and the point-of-sale application.
It distinguishes three kinds of data: data about you as a merchant and your team (for which we are the controller), operational data about how the platform runs, and the customer data your store processes (for which you are the controller and we are your processor).
Read together
This document should be read alongside our Privacy Policy and Cookie Policy, which set out your rights and our cookie use in full.
Categories of Data We Collect
The table below lists the categories we collect and typical examples of each.
| Category | Examples |
|---|---|
| Identity & account | Name, business name, email, phone, hashed password, role. |
| Billing | Plan, invoices, billing address, and limited payment-method details from our processor. |
| Store content | Products, prices, branches, warehouses, staff, suppliers, and settings. |
| Transactional | Sales, invoices, purchases, inventory movements, and accounting entries. |
| Customer records | Customer names, contact details, and purchase history your store enters. |
| Usage & device | Features used, actions taken, IP address, browser/device type, timestamps. |
| Communications | Support messages, feedback, and survey responses. |
No special-category data
We do not seek sensitive data (such as health, religious, or biometric data). Please don’t place it in free-text fields.
Where the Data Comes From
We collect data from a small number of clear sources:
- Directly from you — what you enter when you register, configure your store, and use the platform.
- From your customers — through the transactions and interactions your store records.
- Automatically — technical and usage data generated as you use the service.
- From service providers — for example, the limited billing outcome our payment processor returns.
Purposes & Lawful Bases
Each purpose is tied to a lawful basis, so nothing is processed without a clear reason:
| Purpose | Lawful basis |
|---|---|
| Provide and run your account and store | Contract |
| Bill your subscription and prevent payment fraud | Contract · Legal obligation |
| Secure the platform and prevent abuse | Legitimate interests |
| Improve features and fix problems | Legitimate interests |
| Keep tax and accounting records | Legal obligation |
| Send optional marketing | Consent |
Automated Collection
Some data is generated automatically as the platform operates — for example, log entries, security events, and aggregated usage metrics. We use this to keep the service secure, diagnose issues, and understand which features help.
We do not use this data to make decisions that produce legal or similarly significant effects about you without human involvement.
Data Minimization
We collect the least data a feature needs to work — and prefer to hold none where we can avoid it.
- Optional fields stay optional; we don’t force information a feature doesn’t require.
- Full payment-card numbers are handled by our processor, not stored by us.
- Where aggregated or anonymized data is enough, we use that instead of identifiable data.
Retention Schedule
We keep each category only as long as needed for its purpose or as the law requires. Indicative periods:
| Data | Kept for |
|---|---|
| Active account & store data | While your subscription is active. |
| Data after cancellation | A limited window for export or reactivation, then deleted or anonymized. |
| Invoices & financial records | The period required by tax and accounting law. |
| Security & access logs | A limited period appropriate to their purpose. |
| Support communications | As long as needed to handle your request and for reasonable follow-up. |
Deletion is real
When a retention period ends, data is deleted or irreversibly anonymized — residual backup copies expire on their normal cycle.
Who Receives the Data
We share data only with the recipients described in our Privacy Policy — vetted service providers (sub-processors), your chosen payment processor, integrations you enable, and, where required, authorities. We never sell data, and we bind our sub-processors by contract to protect it.
Your Access & Control
You can see and control much of your data directly:
- View and edit your account, store, and customer records from your dashboard.
- Export your core data in a common, machine-readable format while your subscription is active.
- Request access, correction, or deletion of your personal data as described in the Privacy Policy.
For requests about customer data held inside a store, the merchant is the controller and we will direct the request to them.
Safeguards
The data described here is protected by the measures in our Privacy Policy and Terms of Service: encryption in transit, strict tenant isolation, role-based access, audit logging, and least-privilege access for our team. Report any concern to [email protected].
Changes to This Policy
As we add features, the categories we collect may change. We will update this document, its effective date, and its version, and highlight material changes where appropriate.
Contact Us
Questions about what we collect or how to control it?
- Data & privacy [email protected]
- Security [email protected]
- General [email protected]
- Website storek.com
This summary is provided for convenience only — the full clauses below are what legally apply.
Back to top